First published: Mon May 20 2019(Updated: )
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IBM X-Force ID: 155007
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | >=9.2<=9.2.17 | |
IBM BigFix Platform | >=9.5<=9.5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2005 is considered a medium severity vulnerability that allows local attackers to access sensitive information.
To mitigate CVE-2018-2005, upgrade IBM BigFix Platform to versions 9.2.18 or later, or 9.5.13 or later.
CVE-2018-2005 affects IBM BigFix Platform versions 9.2.x up to 9.2.17 and 9.5.x up to 9.5.12.
CVE-2018-2005 could expose potentially sensitive information stored in process memory to elevated local attackers.
CVE-2018-2005 was disclosed on November 8, 2018.