← Vulnerability feed

Vulnerability record · CVE-2017-1229 · published 13 November 2017

CVE-2017-1229: Ibm bigfix platform information exposure vulnerability

Ibm · Bigfix Platform

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908.

5.9 CVSS 3.0 Medium EPSS 1.2% · top 32.3% CWE-200 · Information exposure
5.9CVSS 3.0 base score, v2 4.3
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.ibm.com/support/docview.wss?uid=swg22005246 Issue TrackingVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/123908 Issue TrackingVDB EntryVendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg22005246 Issue TrackingVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/123908 Issue TrackingVDB EntryVendor Advisory

Track CVE-2017-1229 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-6082Ibm bigfix platform use after free vulnerabilityIBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…EPSS 4.7%9.9CVE-2019-4013Ibm bigfix platform unrestricted file upload vulnerabilityIBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…EPSS 13%9.8CVE-2018-1475Ibm bigfix platform improper restriction of authentication attempts vulnerabilityIBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM…EPSS 2.2%9.8CVE-2017-1221Ibm bigfix platform weak password requirements vulnerabilityIBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for a…EPSS 1.6%8.8CVE-2018-1479Ibm bigfix platform cross-site request forgery vulnerabilityIBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actio…EPSS 0.69%8.8CVE-2016-0295Ibm bigfix platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …EPSS 1.0%8.8CVE-2016-0291Ibm bigfix platform os command injection vulnerabilityIBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report s…EPSS 3.8%8.8CVE-2017-1218Ibm bigfix platform cross-site request forgery vulnerabilityIBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2017-1229), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.