← Vulnerability feed

Vulnerability record · CVE-2016-0396 · published 1 February 2017

CVE-2016-0396: Ibm bigfix platform command injection vulnerability

Ibm · Bigfix Platform

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.

8.1 CVSS 3.0 High EPSS 1.4% · top 28.1% CWE-77 · Command injection
8.1CVSS 3.0 base score, v2 6.8
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0396 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-6082Ibm bigfix platform use after free vulnerabilityIBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…EPSS 4.7%9.9CVE-2019-4013Ibm bigfix platform unrestricted file upload vulnerabilityIBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…EPSS 13%9.8CVE-2018-1475Ibm bigfix platform improper restriction of authentication attempts vulnerabilityIBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM…EPSS 2.2%9.8CVE-2017-1221Ibm bigfix platform weak password requirements vulnerabilityIBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for a…EPSS 1.6%8.8CVE-2018-1479Ibm bigfix platform cross-site request forgery vulnerabilityIBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…EPSS 0.69%8.8CVE-2016-0291Ibm bigfix platform os command injection vulnerabilityIBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…EPSS 3.8%8.8CVE-2016-0295Ibm bigfix platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …EPSS 1.0%8.8CVE-2017-1218Ibm bigfix platform cross-site request forgery vulnerabilityIBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2016-0396), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.