CVE-2018-1481: Infoleak
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1481?
CVE-2018-1481 has a medium severity level due to the potential for sensitive information disclosure.
How do I fix CVE-2018-1481?
To fix CVE-2018-1481, upgrade IBM BigFix Platform to version 9.2.15 or 9.5.10 or later.
What versions of IBM BigFix Platform are affected by CVE-2018-1481?
CVE-2018-1481 affects IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9.
What information can be disclosed due to CVE-2018-1481?
CVE-2018-1481 can lead to the disclosure of sensitive information contained in URL parameters.
Who is vulnerable to CVE-2018-1481?
Organizations using vulnerable versions of IBM BigFix Platform could be exposed to unauthorized information access due to CVE-2018-1481.