CVE-2023-42012Improper Input Validation in IBM Urbancode Deploy

Severity
5.5MEDIUMNVD
CNA6.2
EPSS
0.0%
top 94.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20

Description

An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/urbancode_deploy7.27.2.3.7+1
NVDibm/urbancode_deploy7.2.0.07.2.3.7+1

🔴Vulnerability Details

2
GHSA
GHSA-wvhj-q93v-gc3x: An IBM UrbanCode Deploy Agent 72023-12-20
CVEList
IBM UrbanCode Deploy denial of service2023-12-19
CVE-2023-42012 — Improper Input Validation in IBM | cvebase