IBM Security Bulletin: BigFix Platform 9.5.x / 9.2.x affected by multiple vulnerabilities (CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301)

There are vulnerabilities in the OpenSSL and LibcURL libraries used by BigFix. These are addressed in the BigFix Platform 9.5.11 and 9.2.16 releases.

CVE(s): CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10743283
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144658
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141679
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/149359
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/143390

The post IBM Security Bulletin: BigFix Platform 9.5.x / 9.2.x affected by multiple vulnerabilities (CVE-2018-0732, CVE-2018-0737, CVE-2018-14618, CVE-2018-1000301) appeared first on IBM PSIRT Blog.

Affected IBM BigFix Platform

Affected Versions
BigFix Platform9.5 – 9.5.10
BigFix Platform9.2 – 9.2.15


from IBM Product Security Incident Response Team https://ibm.co/2HqMgxo