← All CVEs

CVE-2019-4061

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.

5.3
CVSS
22.5%
EPSS (exploit prob.)
98th
EPSS percentile
2019-02-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
ibmbigfix_platform>= 9.2, <= 9.2.16
ibmbigfix_platform>= 9.5, <= 9.5.11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-4061