IBM BigFix Platform 9.2 and 9.5 contains an information disclosure vulnerability caused by not enabling authenticated access in relay, letting remote attackers query and gather update and fixlet information, exploit requires no authentication.
id: CVE-2019-4061
info:
name: IBM BigFix Platform - Information Disclosure
author: daffainfo
...