CVE-2023-42013Information Exposure via Error Message in IBM Urbancode Deploy

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 83.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20

Description

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/urbancode_deploy7.17.1.2.14+2
NVDibm/urbancode_deploy7.0.0.07.0.5.18+3

🔴Vulnerability Details

2
GHSA
GHSA-hwgp-86hh-xvg8: IBM UrbanCode Deploy (UCD) 72023-12-20
CVEList
IBM UrbanCode Deploy information disclosure2023-12-19
CVE-2023-42013 — Information Exposure via Error Message | cvebase