CVE-2017-1222: Medium severity hcltech bigfix platform vulnerability
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1222?
CVE-2017-1222 is considered a critical vulnerability due to its potential to allow unauthorized access to protected resources.
How do I fix CVE-2017-1222?
To fix CVE-2017-1222, it is recommended to apply the latest security patches provided by IBM for the affected versions of BigFix Platform.
What versions of IBM BigFix are affected by CVE-2017-1222?
CVE-2017-1222 affects IBM BigFix Platform versions 9.2 and 9.5.
What types of attacks can be conducted due to CVE-2017-1222?
Due to CVE-2017-1222, attackers can exploit the vulnerability to gain unauthorized access to sensitive areas of the application.
Is CVE-2017-1222 a web application vulnerability?
Yes, CVE-2017-1222 is categorized as a web application vulnerability as it relates to authentication mechanisms in IBM Tivoli Endpoint Manager.