CVE-2018-2005: Infoleak
Published May 20, 2019
·Updated
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IBM X-Force ID: 155007
Affected Software
2 affected components
IBM BigFix Platform>=9.2<=9.2.17
IBM BigFix Platform>=9.5<=9.5.12
Event History
May 20, 2019
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2005?
CVE-2018-2005 is considered a medium severity vulnerability that allows local attackers to access sensitive information.
2
How do I fix CVE-2018-2005?
To mitigate CVE-2018-2005, upgrade IBM BigFix Platform to versions 9.2.18 or later, or 9.5.13 or later.
3
Who is affected by CVE-2018-2005?
CVE-2018-2005 affects IBM BigFix Platform versions 9.2.x up to 9.2.17 and 9.5.x up to 9.5.12.
4
What types of information could be exposed by CVE-2018-2005?
CVE-2018-2005 could expose potentially sensitive information stored in process memory to elevated local attackers.
5
When was CVE-2018-2005 disclosed?
CVE-2018-2005 was disclosed on November 8, 2018.