CVE-2016-8938Improper Access Control in Corporation Urbancode Deploy

Severity
10.0CRITICALNVD
EPSS
0.8%
top 26.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages2 packages

NVDibm/urbancode_deploy42 versions+41
CVEListV5ibm_corporation/urbancode_deploy42 versions+41

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6p5x-3fqf-87hc: IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server2022-05-17
CVEList
CVE-2016-8938: IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server2017-02-01
CVE-2016-8938 — Improper Access Control | cvebase