First published: Thu Oct 26 2017(Updated: )
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | =9.2 | |
IBM BigFix Platform | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1222 is considered a critical vulnerability due to its potential to allow unauthorized access to protected resources.
To fix CVE-2017-1222, it is recommended to apply the latest security patches provided by IBM for the affected versions of BigFix Platform.
CVE-2017-1222 affects IBM BigFix Platform versions 9.2 and 9.5.
Due to CVE-2017-1222, attackers can exploit the vulnerability to gain unauthorized access to sensitive areas of the application.
Yes, CVE-2017-1222 is categorized as a web application vulnerability as it relates to authentication mechanisms in IBM Tivoli Endpoint Manager.