IBM Security Bulletin: BigFix Platform 9.5.x affected by vulnerability CVE-2017-1231

The BigFix Platform Version 9.5 exhibits a problem in the area of secure credential storage. This vulnerability has been addressed in patch release 9.5.10.

CVE(s): CVE-2017-1231

Affected product(s) and affected version(s):

Affected IBM BigFix PlatformAffected Versions
BigFix Platform9.5 – 9.5.9

This vulnerability only affects Linux/Unix platforms and affects the credentials related to Server, Web Reports, Relay and Client components that were previously stored in an obfuscated format, and now are encrypted.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10724511
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/123910

The post IBM Security Bulletin: BigFix Platform 9.5.x affected by vulnerability CVE-2017-1231 appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ibm.co/2RLUgZx