{"api_version":"1","generated_at":"2026-07-23T08:53:12+00:00","cve":"CVE-2017-1221","urls":{"html":"https://cve.report/CVE-2017-1221","api":"https://cve.report/api/cve/CVE-2017-1221.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-1221","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-1221"},"summary":{"title":"CVE-2017-1221","description":"IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.","state":"PUBLISHED","assigner":"ibm","published_at":"2017-11-13 23:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-521","Obtain Information"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/101683","name":"http://www.securityfocus.com/bid/101683","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM BigFix Platform CVE-2017-1221 Security Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg22010177","name":"http://www.ibm.com/support/docview.wss?uid=swg22010177","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-1221","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1221","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"BigFix Platform","version":"affected 9.2","platforms":[]},{"source":"CNA","vendor":"IBM","product":"BigFix Platform","version":"affected 9.5","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"1221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_platform","cpe6":"9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_platform","cpe6":"9.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"1221","cve":"CVE-2017-1221","epss":"0.002610000","percentile":"0.494940000","score_date":"2026-05-13","updated_at":"2026-05-14 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T13:25:17.464Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"101683","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/101683"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg22010177"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"BigFix Platform","vendor":"IBM","versions":[{"status":"affected","version":"9.2"},{"status":"affected","version":"9.5"}]}],"datePublic":"2017-10-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861."}],"problemTypes":[{"descriptions":[{"description":"Obtain Information","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-14T10:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"101683","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/101683"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg22010177"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2017-10-31T00:00:00","ID":"CVE-2017-1221","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BigFix Platform","version":{"version_data":[{"version_value":"9.2"},{"version_value":"9.5"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"101683","refsource":"BID","url":"http://www.securityfocus.com/bid/101683"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123861"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg22010177","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg22010177"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2017-1221","datePublished":"2017-11-13T23:00:00.000Z","dateReserved":"2016-11-30T00:00:00.000Z","dateUpdated":"2024-09-17T03:02:31.456Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-13 23:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-521","Obtain Information"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*","matchCriteriaId":"EDF3A293-36B6-41F3-87CE-EC2D89F212B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:bigfix_platform:9.5:*:*:*:*:*:*:*","matchCriteriaId":"9E59DD27-6637-4D89-867B-650AAD2F14B2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"1221","Ordinal":"1","Title":"CVE-2017-1221","CVE":"CVE-2017-1221","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"1221","Ordinal":"1","NoteData":"IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.","Type":"Description","Title":"CVE-2017-1221"},{"CveYear":"2017","CveId":"1221","Ordinal":"2","NoteData":"2017-11-13","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"1221","Ordinal":"3","NoteData":"2017-11-14","Type":"Other","Title":"Modified"}]}}}