IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Link | Tags |
---|---|
https://www-304.ibm.com/support/docview.wss?uid=swg21972041 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/105197 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV81388 | vendor advisory |