CVE-2016-2963: IBM Bigfix Remote Control

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Affected products

  • IBM Bigfix Remote Control: up to and including 9.1.2

Published 2016-11-30. Last modified 2026-06-17.