CVE-2017-1223: Medium severity IBM BigFix Platform vulnerability
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1223?
CVE-2017-1223 is classified as a high severity vulnerability due to its potential to allow remote phishing attacks.
How do I fix CVE-2017-1223?
To fix CVE-2017-1223, you should upgrade to the latest version of IBM BigFix Platform that contains the security patches.
Who is affected by CVE-2017-1223?
CVE-2017-1223 affects users of IBM BigFix Platform version 9.2.6, 9.2.7, and versions in the 9.5 series.
What kind of attack can be conducted through CVE-2017-1223?
CVE-2017-1223 allows a remote attacker to conduct phishing attacks via an open redirect exploit.
What are the potential risks of CVE-2017-1223?
The risks of CVE-2017-1223 include compromising user credentials and redirecting users to malicious websites.