Vulnerability Bulletins

IBM Security Bulletin: A vulnerability in the IBM BixFix Platform could allow passwords to be transmitted in clear text (CVE-2016-0292, CVE-2016-0397)

   
Affected software IBM
 
Web Reports/BigFix Platform passwords are transmitted in clear text by default. WebReports should be configured to use HTTPSCVE(s): CVE-2016-0292, CVE-2016-0397Affected product(s) and affected version(s):9.0, 9.1, 9.2, 9.5Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21985907X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/111303X-Force Database:

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-a-vulnerability-in-the-ibm-bixfix-platform-could-allow-passwords-to-be-transmitted-in-clear-text-cve-2016-0292-cve-2016-0397/