CVE-2017-1231: High severity hcltech bigfix platform vulnerability
Published Oct 12, 2018
·Updated
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.
Affected Software
1 affected component
IBM BigFix Platform>=9.5<=9.5.9
Event History
Oct 12, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1231?
CVE-2017-1231 is considered to have a medium severity due to the exposure of user credentials.
2
How do I fix CVE-2017-1231?
To fix CVE-2017-1231, update the IBM BigFix Platform to a version higher than 9.5.9 that addresses the credential storage issue.
3
What versions of IBM BigFix Platform are affected by CVE-2017-1231?
IBM BigFix Platform versions from 9.5 to 9.5.9 are affected by CVE-2017-1231.
4
What are the potential impacts of CVE-2017-1231?
The impact of CVE-2017-1231 includes unauthorized access to user credentials, compromising the security of the affected system.
5
Is there a workaround for CVE-2017-1231?
While the recommended solution is to upgrade the software, limiting user access to the system can act as a temporary workaround for CVE-2017-1231.