CVE-2015-4964IBM Urbancode Deploy vulnerability

CWE-2643 documents3 sources
Severity
6.0MEDIUMNVD
EPSS
1.8%
top 17.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6
Latest updateMay 17

Description

IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages1 packages

NVDibm/urbancode_deploy20 versions+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r392-2grh-9xm9: IBM UrbanCode Deploy 62022-05-17
CVEList
CVE-2015-4964: IBM UrbanCode Deploy 62015-10-05
CVE-2015-4964 — IBM Urbancode Deploy vulnerability | cvebase