Ibm Urbancode Deploy vulnerabilities
66 known vulnerabilities affecting ibm/urbancode_deploy.
Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM49LOW2
Vulnerabilities
Page 2 of 4
CVE-2016-0365P4MEDIUMCVSS 5.9v6.0v6.0.1.0+34 more2016-07-01
CVE-2016-0365 [MEDIUM] CWE-200 CVE-2016-0365: IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when age
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.
nvd
CVE-2014-8900P4HIGHCVSS 8.8≤ 6.0.1.6≤ 6.1.0.7+1 more2017-08-28
CVE-2014-8900 [HIGH] CWE-352 CVE-2014-8900: Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
nvd
CVE-2017-1749P4MEDIUMCVSS 5.3≥ 6.1, ≤ 6.9.6.0v6.1.0.2+39 more2018-08-13
CVE-2017-1749 [MEDIUM] CWE-22 CVE-2017-1749: IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on th
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
nvd
CVE-2023-47161P4MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.5.18≥ 7.1.0.0, ≤ 7.1.2.14+5 more2023-12-20
CVE-2023-47161 [MEDIUM] CWE-20 CVE-2023-47161: IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mi
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. IBM X-Force ID: 270799.
nvd
CVE-2024-56469P4MEDIUMCVSS 6.3≥ 7.1.0.0, < 7.1.2.23≥ 7.2.0.0, < 7.2.3.16+4 more2025-03-27
CVE-2024-56469 [MEDIUM] CWE-306 CVE-2024-56469: IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IB
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
nvd
CVE-2015-4964P4MEDIUMCVSS 6.0v6.0v6.0.1.0+18 more2015-10-06
CVE-2015-4964 [MEDIUM] CWE-264 CVE-2015-4964: IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
nvd
CVE-2025-36360P4MEDIUMCVSS 5.0≥ 7.1.0.0, < 7.1.2.28≥ 7.2.0.0, < 7.2.3.21+1 more2025-12-15
CVE-2025-36360 [MEDIUM] CWE-613 CVE-2025-36360: IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated
nvd
CVE-2019-4667P4MEDIUMCVSS 5.9v7.0.5.22020-05-11
CVE-2019-4667 [MEDIUM] CWE-319 CVE-2019-4667: IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, ca
IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 171249.
nvd
CVE-2020-4848P4MEDIUMCVSS 5.4v6.2.7.9v7.0.5.4+1 more2021-03-30
CVE-2020-4848 [MEDIUM] CVE-2020-4848: IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initia
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that they should not have access to. IBM X-Force ID: 190293.
nvd
CVE-2024-22359P4MEDIUMCVSS 6.1≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+6 more2024-04-12
CVE-2024-22359 [MEDIUM] CWE-79 CVE-2024-22359: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d
nvd
CVE-2017-1493P4MEDIUMCVSS 5.4v6.1v6.1.0.1+45 more2018-01-09
CVE-2017-1493 [MEDIUM] CWE-269 CVE-2017-1493: IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they s
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.
nvd
CVE-2024-45091P4MEDIUMCVSS 5.5≥ 7.0.0.0, < 7.0.5.25≥ 7.1.0.0, < 7.1.2.21+4 more2025-01-21
CVE-2024-45091 [MEDIUM] CWE-532 CVE-2024-45091: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stor
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
nvd
CVE-2025-1998P4MEDIUMCVSS 5.5≥ 7.1.0.0, < 7.1.2.22≥ 7.2.0.0, < 7.2.3.15+4 more2025-03-27
CVE-2025-1998 [MEDIUM] CWE-532 CVE-2025-1998: IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM Dev
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1
stores potentially sensitive authentication token information in log files that could be read by a local user.
nvd
CVE-2026-12086P4MEDIUMCVSS 5.5≥ 7.2.0.0, < 7.2.3.24≥ 7.3.0.0, < 7.3.2.192026-06-30
CVE-2026-12086 [MEDIUM] CWE-532 CVE-2026-12086: IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevO
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 stores potentially sensitive information in log files that could be read by a local user.
nvd
CVE-2024-28781P4MEDIUMCVSS 5.4≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+7 more2024-05-14
CVE-2024-28781 [MEDIUM] CWE-79 CVE-2024-28781: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a
nvd
CVE-2023-42013P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.5.18≥ 7.1.0.0, ≤ 7.1.2.14+5 more2023-12-20
CVE-2023-42013 [MEDIUM] CWE-209 CVE-2023-42013: IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510.
nvd
CVE-2017-1752P4MEDIUMCVSS 4.9≥ 6.1, ≤ 6.1.3.8≥ 6.2, ≤ 6.2.7.0+43 more2018-05-25
CVE-2017-1752 [MEDIUM] CWE-200 CVE-2017-1752: IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensi
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.
nvd
CVE-2022-40751P4MEDIUMCVSS 4.9≥ 6.2.7.0, < 6.2.7.18≥ 7.0.0.0, < 7.0.5.13+6 more2022-11-17
CVE-2022-40751 [MEDIUM] CWE-522 CVE-2022-40751: IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID:
236601.
nvd
CVE-2019-4668P4MEDIUMCVSS 5.5fixed in 7.0.4.0v7.0.4.02020-04-23
CVE-2019-4668 [MEDIUM] CWE-522 CVE-2019-4668: IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.
nvd
CVE-2016-9006P4MEDIUMCVSS 5.4v6.1v6.1.0.1+27 more2017-03-08
CVE-2016-9006 [MEDIUM] CWE-79 CVE-2016-9006: IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows us
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.
nvd