PT-2022-24505 · Ibm · Bigfix Webui

Published

2022-12-20

·

Updated

2022-12-28

·

CVE-2022-38655

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions BigFix WebUI (affected versions not specified)
Description The issue concerns BigFix WebUI non-master operators who are missing necessary controls. These operators can modify the relevance of fixlets or deploy fixlets from the BES Support external site without proper restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-38655

Affected Products

Bigfix Webui