IBM Security Bulletin: BigFix Family WebUI Component Has Security Vulnerabilities
The BigFix WebUI has vulnerabilities in the following categories: Spoofing through URL redirection, Use of a broken or risky cryptographic algorithm, Cross site scripting and Cross site request forgery
CVE(s): CVE-2017-1223, CVE-2017-1224, CVE-2017-1203, CVE-2017-1218
Affected product(s) and affected version(s):
All BigFix Family WebUI Application subscriptions. These can run in BigFix Platform Versions 9.2.6 and greater.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2tBWuP3
X-Force Database: http://ift.tt/2u6eXXH
X-Force Database: http://ift.tt/2tBKzkv
X-Force Database: http://ift.tt/2u5UwKc
X-Force Database: http://ift.tt/2u5GeJS
The post IBM Security Bulletin: BigFix Family WebUI Component Has Security Vulnerabilities appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2tCkrG8