CVE-2023-42015

Severity
4.3MEDIUM
EPSS
0.1%
top 81.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/urbancode_deploy7.1.0.07.1.2.15+2
CVEListV5ibm/urbancode_deploy7.17.1.2.14+2

🔴Vulnerability Details

2
GHSA
GHSA-9m37-9693-4vqx: IBM UrbanCode Deploy (UCD) 72023-12-19
CVEList
IBM UrbanCode Deploy HTML injection2023-12-19
CVE-2023-42015 (MEDIUM CVSS 4.3) | IBM UrbanCode Deploy (UCD) 7.1 thro | cvebase.io