Ibm

License Metric Tool

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 01.02.2017 20:59:03
  • Last modified 20.04.2025 01:37:25

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displa...

  • EPSS 0.14%
  • Published 11.10.2015 01:59:00
  • Last modified 12.04.2025 10:46:40

IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request.

  • EPSS 0.57%
  • Published 25.05.2015 14:59:06
  • Last modified 12.04.2025 10:46:40

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of servi...

  • EPSS 0.57%
  • Published 25.05.2015 14:59:05
  • Last modified 12.04.2025 10:46:40

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of servi...

  • EPSS 0.22%
  • Published 25.05.2015 14:59:02
  • Last modified 12.04.2025 10:46:40

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking atta...

  • EPSS 0.1%
  • Published 25.05.2015 14:59:00
  • Last modified 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via ...

  • EPSS 0.29%
  • Published 20.05.2015 10:59:01
  • Last modified 12.04.2025 10:46:40

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via ...

  • EPSS 0.2%
  • Published 20.05.2015 10:59:00
  • Last modified 12.04.2025 10:46:40

IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.