IBM BigFix Platform 9.x < 9.1.9 / 9.2.x < 9.2.9 / 9.5.x < 9.5.4 Multiple Vulnerabilities

Critical Nessus Plugin ID 96626


An infrastructure management application running on the remote host is affected by multiple vulnerabilities.


According to its self-reported version, the IBM BigFix Platform application running on the remote host is 9.x prior to 9.1.9, 9.2.x prior to 9.2.9, or 9.5.x prior to 9.5.4. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists due to a use-after-free race condition. An unauthenticated, remote attacker can exploit this to execute arbitrary code.

- A denial of service vulnerability exists that is triggered when handling specially crafted XMLSchema requests. An unauthenticated, adjacent attacker can exploit this to crash the BES Server. Note that this issue only affects 9.0.x or 9.1.x versions prior to 9.1.9. (CVE-2016-6084)

- A denial of service vulnerability exists in the BES Root Server and BES Relay Memory when handling unspecified user-supplied input. An unauthenticated, adjacent attacker can exploit this to cause the system to crash.

Note that, additionally, several vulnerabilities possibly also exist in the bundled version of OpenSSL included in versions 9.0.x.

IBM BigFix Platform was formerly known as Tivoli Endpoint Manager, IBM Endpoint Manager, and IBM BigFix Endpoint Manager.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Upgrade to IBM BigFix Platform version 9.1.9 / 9.2.9 / 9.5.4 or later.

See Also

Plugin Details

Severity: Critical

ID: 96626

File Name: ibm_bigfix_webreports_2016_6082.nasl

Version: $Revision: 1.4 $

Type: remote

Family: Misc.

Published: 2017/01/19

Modified: 2017/07/27

Dependencies: 94962

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 10

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/a:ibm:bigfix_platform

Required KB Items: installed_sw/IBM BigFix Web Reports

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/12/20

Vulnerability Publication Date: 2016/12/20

Reference Information

CVE: CVE-2016-6082, CVE-2016-6084, CVE-2016-6085

BID: 95286, 95291, 95297

OSVDB: 149108, 149109, 149224