IBM Security Bulletin: Weak default password lockout policy in IBM BigFix Compliance Analytics (CVE-2017-1197)

IBM BigFix Compliance Analytics uses an inadequate default account lockout setting that could allow a remote attacker to brute force account credentials. IBM BigFix Compliance Analytics has remediated this vulnerability.

CVE(s): CVE-2017-1197

Affected product(s) and affected version(s):

IBM BigFix Security Compliance Analytics 1.9.70

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2solgpN
X-Force Database: http://ift.tt/2sXL8FU

The post IBM Security Bulletin: Weak default password lockout policy in IBM BigFix Compliance Analytics (CVE-2017-1197) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2sowDhk