IBM BigFix Compliance versions 1.7 through 1.9.91 are vulnerable to information disclosure (CVE-2017-1198). This vulnerability, categorized as CWE-532, involves the storage of sensitive information within URL parameters. This could expose data through server logs, referrer headers, or browser history if unauthorized individuals gain access to these URLs. With a CVSSv3 score of 5.3 (Medium), the vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and primarily impacts confidentiality. The EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also non-existent, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7, <= 1.9.91CPE matchmatch criteria | cpe:2.3:a:ibm:bigfix_compliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.