CVE-2018-1484: Medium severity hcltech bigfix platform vulnerability
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 140969.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1484?
CVE-2018-1484 is classified as a medium severity vulnerability due to the risk of session hijacking.
How do I fix CVE-2018-1484?
To fix CVE-2018-1484, ensure that the secure attribute is set on all authorization tokens and session cookies in the IBM BigFix Platform.
What versions of IBM BigFix Platform are affected by CVE-2018-1484?
CVE-2018-1484 affects IBM BigFix Platform versions 9.2.0 to 9.2.14 and 9.5 to 9.5.9.
What are the consequences of CVE-2018-1484?
The consequences of CVE-2018-1484 include potential exposure of user session information, allowing attackers to impersonate users.
Is authentication impacted by CVE-2018-1484?
CVE-2018-1484 specifically impacts session security but does not directly affect the authentication process itself.