PatchSiren cyber security CVE debrief
CVE-2016-8967 IBM CVE debrief
CVE-2016-8967 is a credential exposure issue in IBM BigFix Inventory 9.2. According to the NVD description, user credentials are stored in clear text and can be read by a local user. The NVD CVSS 3.0 vector reflects local access with low privileges and high confidentiality impact.
- Vendor
- IBM
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for IBM BigFix Inventory 9.2 and the related IBM License Metric Tool 9.2.0 deployments should care, especially where multiple local users or shared administrative access exist.
Technical summary
The NVD record states that IBM BigFix Inventory v9 9.2 stores user credentials in plain text, allowing a local user to read them. The CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating a local, low-privilege confidentiality exposure with no direct integrity or availability impact. NVD also associates the issue with IBM License Metric Tool 9.2.0 in its CPE criteria and lists CWE-255.
Defensive priority
Medium. The issue does not require remote access, but it can expose credentials to any attacker or insider who can obtain local access on an affected system.
Recommended defensive actions
- Review the IBM advisory referenced by NVD for vendor guidance on remediation or mitigation.
- Restrict local access to affected systems and minimize the number of users with shell or interactive access.
- Identify deployments matching the affected NVD CPEs: IBM BigFix Inventory 9.2 and IBM License Metric Tool 9.2.0.
- Rotate any credentials that may have been stored in clear text on affected systems.
- Validate that sensitive secrets are not stored in readable files on the host and review local permissions around application data and configuration locations.
Evidence notes
Evidence is drawn from the NVD record for CVE-2016-8967, which describes clear-text credential storage readable by a local user and assigns CVSS 3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The record references IBM PSIRT guidance and a SecurityFocus entry, and the CPE criteria mark IBM BigFix Inventory 9.2 and IBM License Metric Tool 9.2.0 as vulnerable. CWE-255 is listed as the primary weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8967 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8967
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8967 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8967
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.