CVE-2017-1218: CSRF
Published Jul 19, 2017
·Updated
IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.
Affected Software
5 affected components
IBM BigFix Platform=9.2.6
IBM BigFix Platform=9.2.7
IBM BigFix Platform=9.5
IBM BigFix Platform=9.5.5
IBM BigFix Platform=9.5.6
Event History
Jul 19, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1218?
CVE-2017-1218 is considered a medium severity vulnerability due to its potential for unauthorized actions.
2
How do I fix CVE-2017-1218?
To fix CVE-2017-1218, upgrade to the latest version of IBM Tivoli Endpoint Manager which addresses the cross-site request forgery issue.
3
Which versions of IBM BigFix Platform are affected by CVE-2017-1218?
IBM BigFix Platform versions 9.2.6, 9.2.7, 9.5, 9.5.5, and 9.5.6 are affected by CVE-2017-1218.
4
What type of vulnerability is CVE-2017-1218?
CVE-2017-1218 is a cross-site request forgery vulnerability.
5
Who is impacted by CVE-2017-1218?
Users of IBM Tivoli Endpoint Manager who rely on its trusted actions are impacted by CVE-2017-1218.