CVE-2016-8964: IBM Bigfix Inventory

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.

Affected products

  • IBM Bigfix Inventory: from 9.0, before 9.2.8 (fixed in 9.2.8)
  • IBM License Metric Tool: from 9.0, before 9.2.8 (fixed in 9.2.8)

Published 2017-07-13. Last modified 2026-06-17.