CVE-2018-1479: CSRF
Published Apr 27, 2018
·Updated
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761.
Affected Software
2 affected components
IBM BigFix Platform>=9.2<=9.2.13
IBM BigFix Platform>=9.5<=9.5.8
Remediation
Patch Available
Event History
Apr 27, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1479?
CVE-2018-1479 is classified as a medium severity vulnerability due to the potential for cross-site request forgery attacks.
2
How do I fix CVE-2018-1479?
To fix CVE-2018-1479, users should upgrade to IBM BigFix Platform version 9.5.9 or later.
3
What is the impact of CVE-2018-1479?
CVE-2018-1479 allows attackers to perform unauthorized actions on behalf of trusted users.
4
Which versions of IBM BigFix are affected by CVE-2018-1479?
CVE-2018-1479 affects IBM BigFix Platform versions 9.2 through 9.2.13 and 9.5 through 9.5.8.
5
Is CVE-2018-1479 specific to any operating system?
CVE-2018-1479 is not specific to any operating system, but rather affects the IBM BigFix Platform itself.