IBM Security Bulletin: BigFix Family WebUI Component Has Security Vulnerabilities

The BigFix WebUI has vulnerabilities in the following categories: Spoofing through URL redirection, Use of a broken or risky cryptographic algorithm, Cross site scripting and Cross site request forgery

CVE(s): CVE-2017-1223, CVE-2017-1224, CVE-2017-1203, CVE-2017-1218

Affected product(s) and affected version(s):

All BigFix Family WebUI Application subscriptions. These can run in BigFix Platform Versions 9.2.6 and greater.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2tBWuP3
X-Force Database: http://ift.tt/2u6eXXH
X-Force Database: http://ift.tt/2tBKzkv
X-Force Database: http://ift.tt/2u5UwKc
X-Force Database: http://ift.tt/2u5GeJS

The post IBM Security Bulletin: BigFix Family WebUI Component Has Security Vulnerabilities appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2tCkrG8