CVE-2016-0320Improper Access Control in Corporation Urbancode Deploy

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 68.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/urbancode_deploy42 versions+41
CVEListV5ibm_corporation/urbancode_deploy42 versions+41

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8h67-hvhq-252w: IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD2022-05-17
CVEList
CVE-2016-0320: IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD2017-02-01
CVE-2016-0320 — Improper Access Control | cvebase