cbcvebase.

Ibm Urbancode Deploy vulnerabilities

66 known vulnerabilities affecting ibm/urbancode_deploy.

Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM49LOW2

Vulnerabilities

Page 3 of 4
CVE-2024-22331P4MEDIUMCVSS 5.5≥ 7.0.0.0, < 7.0.5.20≥ 7.1.0.0, < 7.1.2.16+6 more2024-02-06
CVE-2024-22331 [MEDIUM] CWE-200 CVE-2024-22331: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 thro IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971.
nvd
CVE-2020-4884P4MEDIUMCVSS 5.5v6.2.7.9v7.0.5.4+1 more2021-03-30
CVE-2020-4884 [MEDIUM] CWE-312 CVE-2020-4884: IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear t IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
nvd
CVE-2022-22367P4MEDIUMCVSS 5.5v6.2.7.15v7.0.5.10+2 more2022-07-01
CVE-2022-22367 [MEDIUM] CWE-312 CVE-2022-22367: IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive databas IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
nvd
CVE-2016-2994P4MEDIUMCVSS 5.4v6.2.0.0v6.2.0.1+4 more2016-12-01
CVE-2016-2994 [MEDIUM] CWE-79 CVE-2016-2994: Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-2941P4MEDIUMCVSS 5.5v6.0v6.0.1+40 more2017-02-01
CVE-2016-2941 [MEDIUM] CWE-200 CVE-2016-2941: IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive info IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
nvd
CVE-2022-43877P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.7.20≥ 7.0.0.0, < 7.0.5.15+8 more2023-05-06
CVE-2022-43877 [MEDIUM] CWE-922 CVE-2022-43877: IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information duri IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.
nvd
CVE-2020-4944P4MEDIUMCVSS 5.5v7.0.3.0v7.0.4.0+6 more2021-03-30
CVE-2020-4944 [MEDIUM] CWE-312 CVE-2020-4944: IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1. IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
nvd
CVE-2025-1997P4MEDIUMCVSS 4.6≥ 7.0.0.0, < 7.0.5.26≥ 7.1.0.0, < 7.1.2.22+6 more2025-03-27
CVE-2025-1997 [MEDIUM] CWE-80 CVE-2025-1997: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
nvd
CVE-2015-7415P4MEDIUMCVSS 5.4v6.0v6.0.1.0+25 more2016-01-01
CVE-2015-7415 [MEDIUM] CWE-79 CVE-2015-7415: Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2024-22334P4MEDIUMCVSS 4.4≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+5 more2024-04-12
CVE-2024-22334 [MEDIUM] CWE-732 CVE-2024-22334: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated permissions of objects using that type ma
nvd
CVE-2023-42015P4MEDIUMCVSS 4.3≥ 7.1.0.0, < 7.1.2.15≥ 7.2.0.0, < 7.2.3.8+4 more2023-12-19
CVE-2023-42015 [MEDIUM] CWE-79 CVE-2023-42015: IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vul IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.
nvd
CVE-2024-22339P4MEDIUMCVSS 4.3≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+6 more2024-04-12
CVE-2024-22339 [MEDIUM] CWE-532 CVE-2024-22339: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM X-Force ID: 279979.
nvd
CVE-2022-46771P4MEDIUMCVSS 4.6≥ 6.2.0.0, ≤ 6.2.7.18≥ 7.0.5.0, ≤ 7.0.5.13+7 more2022-12-20
CVE-2022-46771 [MEDIUM] CWE-79 CVE-2022-46771: IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1. IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within
nvd
CVE-2021-29711P4MEDIUMCVSS 4.3v6.2.7.3v7.0.3.0+9 more2021-07-08
CVE-2021-29711 [MEDIUM] CVE-2021-29711: IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.
nvd
CVE-2025-36162P4MEDIUMCVSS 4.3≥ 8.1, ≤ 8.1.2.12025-09-02
CVE-2025-36162 [MEDIUM] CWE-497 CVE-2025-36162: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.
nvd
CVE-2016-0364P4MEDIUMCVSS 4.3v6.0v6.0.1.0+34 more2016-07-01
CVE-2016-0364 [MEDIUM] CWE-200 CVE-2016-0364: IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
nvd
CVE-2020-4484P4MEDIUMCVSS 4.3v6.2.7.3v6.2.7.4+2 more2020-11-06
CVE-2020-4484 [MEDIUM] CVE-2020-4484: IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive informati IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force ID: 181858.
nvd
CVE-2016-0373P4MEDIUMCVSS 4.3≥ 6.0, ≤ 6.2.2.1v6.1.0.2+41 more2018-08-30
CVE-2016-0373 [MEDIUM] CWE-285 CVE-2016-0373: IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive informa IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
nvd
CVE-2016-0320P4MEDIUMCVSS 4.3v6.0v6.0.1+40 more2017-02-01
CVE-2016-0320 [MEDIUM] CWE-284 CVE-2016-0320: IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST en IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
nvd
CVE-2023-42012P4MEDIUMCVSS 5.5≥ 7.2.0.0, ≤ 7.2.3.7≥ 7.3.0.0, ≤ 7.3.2.2+2 more2023-12-20
CVE-2023-42012 [MEDIUM] CWE-20 CVE-2023-42012: An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows se An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509.
nvd
Ibm Urbancode Deploy vulnerabilities | cvebase