CVE-2017-1228: Infoleak
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123907.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1228?
CVE-2017-1228 is considered a high-severity vulnerability that can lead to sensitive information disclosure.
How do I fix CVE-2017-1228?
To fix CVE-2017-1228, ensure that the secure cookie attribute is properly enabled in your IBM BigFix Platform configuration.
Who is affected by CVE-2017-1228?
CVE-2017-1228 affects users of IBM Tivoli Endpoint Manager running versions 9.2 and 9.5 of the IBM BigFix Platform.
What type of attack is associated with CVE-2017-1228?
CVE-2017-1228 is associated with man-in-the-middle attacks that can exploit the vulnerability to obtain sensitive information.
When was CVE-2017-1228 disclosed?
CVE-2017-1228 was disclosed in 2017 and is part of ongoing security discussions related to IBM software vulnerabilities.