IBM Security Bulletin: BigFix Platform 9.5.x affected by vulnerability CVE-2017-1231
The BigFix Platform Version 9.5 exhibits a problem in the area of secure credential storage. This vulnerability has been addressed in patch release 9.5.10.
CVE(s): CVE-2017-1231
Affected product(s) and affected version(s):
Affected IBM BigFix Platform | Affected Versions |
---|---|
BigFix Platform | 9.5 – 9.5.9 |
This vulnerability only affects Linux/Unix platforms and affects the credentials related to Server, Web Reports, Relay and Client components that were previously stored in an obfuscated format, and now are encrypted.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10724511
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/123910
The post IBM Security Bulletin: BigFix Platform 9.5.x affected by vulnerability CVE-2017-1231 appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ibm.co/2RLUgZx