CVE-2022-22315Improper Privilege Management in IBM Urbancode Deploy

Severity
8.8HIGHNVD
EPSS
0.2%
top 55.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateApr 28

Description

IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/urbancode_deploy6.2.7.06.2.7.15+3
CVEListV5ibm/urbancode_deploy19 versions+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jqvh-rvpj-hvpw: IBM UrbanCode Deploy (UCD) 72022-04-28
CVEList
CVE-2022-22315: IBM UrbanCode Deploy (UCD) 72022-04-27
CVE-2022-22315 — Improper Privilege Management in IBM | cvebase