← Vulnerability feed

Vulnerability record · CVE-2019-4061 · published 27 February 2019

CVE-2019-4061: Ibm bigfix platform information exposure vulnerability

Ibm · Bigfix Platform

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.

5.3 CVSS 3.1 Medium EPSS 23% · top 2.4% CWE-200 · Information exposure
5.3CVSS 3.1 base score, v2 5.0
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-4061 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-6082Ibm bigfix platform use after free vulnerabilityIBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…EPSS 4.7%9.9CVE-2019-4013Ibm bigfix platform unrestricted file upload vulnerabilityIBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…EPSS 13%9.8CVE-2018-1475Ibm bigfix platform improper restriction of authentication attempts vulnerabilityIBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM…EPSS 2.2%9.8CVE-2017-1221Ibm bigfix platform weak password requirements vulnerabilityIBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for a…EPSS 1.6%8.8CVE-2018-1479Ibm bigfix platform cross-site request forgery vulnerabilityIBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…EPSS 0.69%8.8CVE-2016-0291Ibm bigfix platform os command injection vulnerabilityIBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…EPSS 3.8%8.8CVE-2016-0295Ibm bigfix platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …EPSS 1.0%8.8CVE-2017-1218Ibm bigfix platform cross-site request forgery vulnerabilityIBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2019-4061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.