First published: Tue Oct 30 2018(Updated: )
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Security Compliance Analytics | >=1.7<=1.9.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1198 has been classified as a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2017-1198, ensure sensitive information is not included in URL parameters and implement secure coding practices.
CVE-2017-1198 affects IBM BigFix Compliance versions 1.7 through 1.9.91.
CVE-2017-1198 can lead to the disclosure of sensitive information stored in URL parameters.
Unauthorized access in CVE-2017-1198 can occur if URLs containing sensitive information are accessed through server logs, referrer headers, or browser history.