CVE-2018-1479

Severity
8.8HIGH
EPSS
0.1%
top 67.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 14

Description

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/bigfix_platform9.29.2.13+1
CVEListV5ibm/bigfix_platform9.2, 9.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hj32-3rpc-p9j5: IBM BigFix Platform 92022-05-14
CVEList
CVE-2018-1479: IBM BigFix Platform 92018-04-27
CVE-2018-1479 (HIGH CVSS 8.8) | IBM BigFix Platform 9.2 and 9.5 is | cvebase.io