First published: Fri Apr 27 2018(Updated: )
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | >=9.2<=9.2.13 | |
IBM BigFix Platform | >=9.5<=9.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1475 has a medium severity rating due to its potential to allow remote attackers to brute force account credentials.
To fix CVE-2018-1475, you should update IBM BigFix Platform to a version beyond 9.2.13 or 9.5.8 that addresses the account lockout settings.
CVE-2018-1475 affects IBM BigFix Platform versions 9.2 and 9.5 up to 9.2.13 and 9.5.8.
The impact of CVE-2018-1475 allows remote attackers to exploit inadequate lockout settings to gain unauthorized access.
Implementing stronger account lockout policies can act as a temporary workaround for CVE-2018-1475 until a software update is applied.