CVE-2018-1475: Critical severity IBM BigFix Platform vulnerability
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1475?
CVE-2018-1475 has a medium severity rating due to its potential to allow remote attackers to brute force account credentials.
How do I fix CVE-2018-1475?
To fix CVE-2018-1475, you should update IBM BigFix Platform to a version beyond 9.2.13 or 9.5.8 that addresses the account lockout settings.
Which versions of IBM BigFix Platform are affected by CVE-2018-1475?
CVE-2018-1475 affects IBM BigFix Platform versions 9.2 and 9.5 up to 9.2.13 and 9.5.8.
What is the impact of CVE-2018-1475?
The impact of CVE-2018-1475 allows remote attackers to exploit inadequate lockout settings to gain unauthorized access.
Is there a workaround for CVE-2018-1475?
Implementing stronger account lockout policies can act as a temporary workaround for CVE-2018-1475 until a software update is applied.