CVE-2018-1600: High severity hcltech bigfix platform vulnerability
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1600?
CVE-2018-1600 is considered a high severity vulnerability due to the transmission of sensitive data in clear text.
How do I fix CVE-2018-1600?
To mitigate CVE-2018-1600, upgrade to IBM BigFix Platform version 9.5.9 or later, which includes security enhancements.
What systems are affected by CVE-2018-1600?
CVE-2018-1600 affects IBM BigFix Platform versions 9.2 through 9.2.13 and 9.5 through 9.5.8.
What data is at risk with CVE-2018-1600?
Sensitive and security-critical data transmitted over the affected versions of IBM BigFix Platform is at risk of being intercepted by unauthorized actors.
Is CVE-2018-1600 exploitable remotely?
Yes, CVE-2018-1600 can be exploited by an attacker who can access the communication channel.