IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
| Software | From | Fixed in |
|---|---|---|
| ibm / license_metric_tool | 9.2.0 | 9.2.0.x |
| ibm / bigfix_inventory | 9.2 | 9.2.x |