PT-2018-4388 · Ibm · Ibm Bigfix Remote Control

Published

2018-03-27

·

Updated

2018-04-23

·

CVE-2015-4954

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM BigFix Remote Control versions prior to 9.1.2-TIV-IBRC912-IF0001
Description The issue improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors.
Recommendations For versions prior to 9.1.2-TIV-IBRC912-IF0001, apply Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 to resolve the issue. As a temporary workaround, consider restricting the use of self-signed certificates until the fix is applied.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4954

Affected Products

Ibm Bigfix Remote Control