IBM Security Bulletin: Weak default password policy in IBM BigFix Compliance Analytics (CVE-2017-1196)

IBM BigFix Compliance Analytics uses a weak default password policy that could allow an attacker to easily guess user passwords. IBM BigFix Compliance Analytics has remediated this vulnerability.

CVE(s): CVE-2017-1196

Affected product(s) and affected version(s):

IBM BigFix Security Compliance Analytics 1.9.70

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2szw1Cq
X-Force Database: http://ift.tt/2rZXXCo

The post IBM Security Bulletin: Weak default password policy in IBM BigFix Compliance Analytics (CVE-2017-1196) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2sztDMh