CVE-2022-35716Incorrect Authorization in IBM Urbancode Deploy

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 65.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateAug 2

Description

IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/urbancode_deploy6.2.0.06.2.7.17+3
CVEListV5ibm/urbancode_deploy8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-575c-c64w-3q6w: IBM UrbanCode Deploy (UCD) 62022-08-02
CVEList
CVE-2022-35716: IBM UrbanCode Deploy (UCD) 62022-07-31
CVE-2022-35716 — Incorrect Authorization in IBM | cvebase