cbcvebase.
CVE-2025-1998
published 2025-03-27

CVE-2025-1998: IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user.

Affected

20 ranges
VendorProductVersion rangeFixed in
ibmdevops_deploy
ibmdevops_deploy
ibmdevops_deploy8.0 – 8.0.1.4
ibmdevops_deploy>= 8.0.0.0 < 8.0.1.58.0.1.5
ibmurbancode_deploy7.1 – 7.1.2.21
ibmurbancode_deploy>= 7.1.0.0 < 7.1.2.227.1.2.22
ibmurbancode_deploy7.2 – 7.2.3.14
ibmurbancode_deploy>= 7.2.0.0 < 7.2.3.157.2.3.15
ibmurbancode_deploy7.3 – 7.3.2.9
ibmurbancode_deploy>= 7.3.0.0 < 7.3.2.107.3.2.10
msrccbl2_hyperv-daemons_5.15.118.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.111.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.48.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_hyperv-daemons_5.10.189.1-1_on_cbl_mariner_1.0
msrccm1_kernel_5.10.123.1-1_on_cbl_mariner_1.0
msrccm1_kernel_5.10.179.1-1_on_cbl_mariner_1.0