CVE-2016-0293: IBM Bigfix Platform

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.

Affected products

  • IBM Bigfix Platform: version 9.2.0 only; version 9.2.1 only; version 9.2.2 only; version 9.2.3 only; version 9.2.4 only; version 9.2.5 only; …

Published 2016-09-01. Last modified 2026-06-17.