CVE-2025-12985
- EPSS 0.02%
- Veröffentlicht 20.01.2026 14:50:51
- Zuletzt bearbeitet 26.01.2026 15:05:23
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
CVE-2025-36352
- EPSS 0.05%
- Veröffentlicht 29.09.2025 15:16:08
- Zuletzt bearbeitet 03.10.2025 17:54:10
IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t...
CVE-2025-36351
- EPSS 0.08%
- Veröffentlicht 29.09.2025 15:16:08
- Zuletzt bearbeitet 03.10.2025 17:53:55
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
CVE-2023-43044
- EPSS 0.09%
- Veröffentlicht 28.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 08:23:38
IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266...
CVE-2016-8964
- EPSS 2.44%
- Veröffentlicht 13.07.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
CVE-2016-8977
- EPSS 0.23%
- Veröffentlicht 01.02.2017 22:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
CVE-2016-8963
- EPSS 0.05%
- Veröffentlicht 01.02.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
CVE-2016-8967
- EPSS 0.05%
- Veröffentlicht 01.02.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
CVE-2016-8980
- EPSS 0.36%
- Veröffentlicht 01.02.2017 20:59:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all av...
CVE-2016-8981
- EPSS 0.05%
- Veröffentlicht 01.02.2017 20:59:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.