cbcvebase.
CVE-2025-1997
published 2025-03-27

CVE-2025-1997: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4…

medium4.6CVSS 3.1
AVNACLPRLUIRSUCLILAN
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

Affected

12 ranges
VendorProductVersion rangeFixed in
ibmdevops_deploy
ibmdevops_deploy
ibmdevops_deploy8.0 – 8.0.1.4
ibmdevops_deploy>= 8.0.0.0 < 8.0.1.58.0.1.5
ibmurbancode_deploy7.0 – 7.0.5.25
ibmurbancode_deploy>= 7.0.0.0 < 7.0.5.267.0.5.26
ibmurbancode_deploy7.1 – 7.1.2.21
ibmurbancode_deploy>= 7.1.0.0 < 7.1.2.227.1.2.22
ibmurbancode_deploy7.2 – 7.2.3.14
ibmurbancode_deploy>= 7.2.0.0 < 7.2.3.157.2.3.15
ibmurbancode_deploy7.3 – 7.3.2.9
ibmurbancode_deploy>= 7.3.0.0 < 7.3.2.107.3.2.10