IBM Security Bulletin: BigFix Platform 9.5.x / 9.2.x affected by multiple vulnerabilities (CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301)
There are vulnerabilities in the OpenSSL and LibcURL libraries used by BigFix. These are addressed in the BigFix Platform 9.5.11 and 9.2.16 releases.
CVE(s): CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301
Affected product(s) and affected version(s):
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10743283
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144658
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141679
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/149359
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/143390
The post IBM Security Bulletin: BigFix Platform 9.5.x / 9.2.x affected by multiple vulnerabilities (CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301) appeared first on IBM PSIRT Blog.
Affected IBM BigFix Platform | Affected Versions |
BigFix Platform | 9.5 – 9.5.10 |
BigFix Platform | 9.2 – 9.2.15 |
from IBM Product Security Incident Response Team https://ibm.co/2HqMgxo