CVE-2017-1222Improper Authentication in IBM Bigfix Platform

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 60.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 26
Latest updateMay 17

Description

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages1 packages

NVDibm/bigfix_platform9.2, 9.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qw7p-qjwr-4v7h: IBM Tivoli Endpoint Manager (IBM BigFix Platform 92022-05-17
CVEList
CVE-2017-1222: IBM Tivoli Endpoint Manager (IBM BigFix Platform 92017-10-26

💬Community

2
Bugzilla
CVE-2017-14737 botan: cryptographic cache-based side channel in the RSA implementation2017-09-27
Bugzilla
CVE-2017-12481 ledger: stack-based buffer overflow in find_option function2017-08-21
CVE-2017-1222 — Improper Authentication in IBM | cvebase