CVE-2018-1485: Medium severity IBM BigFix Platform vulnerability
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 140970.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1485?
CVE-2018-1485 is classified as having a medium severity due to the potential for session fixation or hijacking.
How do I fix CVE-2018-1485?
To fix CVE-2018-1485, upgrade IBM BigFix Platform to version 9.2.15 or later, or 9.5.10 or later.
What systems are affected by CVE-2018-1485?
CVE-2018-1485 affects IBM BigFix Platform versions from 9.2.0 to 9.2.14 and from 9.5.0 to 9.5.9.
What kind of attacks can result from CVE-2018-1485?
CVE-2018-1485 can lead to session fixation or hijacking attacks, allowing an attacker to impersonate a legitimate user.
Is there a workaround for CVE-2018-1485?
Currently, the recommended action is to apply the latest software updates, as there are no documented workarounds for CVE-2018-1485.