CVE-2016-8938 — Improper Access Control in Corporation Urbancode Deploy
Severity
10.0CRITICALNVD
EPSS
0.8%
top 26.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 1
Latest updateMay 17
Description
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0
Affected Packages2 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-6p5x-3fqf-87hc: IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server↗2022-05-17
CVEList▶
CVE-2016-8938: IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server↗2017-02-01