Description
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1
stores potentially sensitive authentication token information in log files that could be read by a local user.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages4 packages
🔴Vulnerability Details
2GHSAGHSA-wvfh-rj9m-fpc6: IBM UrbanCode Deploy (UCD) through 7↗2025-03-27 ▶ CVEListIBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosure↗2025-03-27 ▶ 📋Vendor Advisories
2MicrosoftSpectre v2 SMT mitigations problem in Linux kernel↗2023-04-11 ▶ MicrosoftA use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this f↗2022-06-14 ▶