CVE-2017-1229: Infoleak
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1229?
CVE-2017-1229 has a medium severity rating due to its potential to allow sensitive information disclosure.
How do I fix CVE-2017-1229?
To mitigate CVE-2017-1229, ensure that HTTP Strict Transport Security is properly enabled on your IBM Tivoli Endpoint Manager installation.
Who is affected by CVE-2017-1229?
CVE-2017-1229 affects users of IBM BigFix versions 9.2 and 9.5.
What types of attacks can exploit CVE-2017-1229?
CVE-2017-1229 can be exploited through man-in-the-middle attacks that allow an attacker to capture sensitive information.
Is CVE-2017-1229 being actively exploited in the wild?
There are no specific reports indicating that CVE-2017-1229 is being actively exploited in the wild, but it remains a security concern.