Ibm Urbancode Deploy vulnerabilities
66 known vulnerabilities affecting ibm/urbancode_deploy.
Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM49LOW2
Vulnerabilities
Page 3 of 4
CVE-2024-22331P4MEDIUMCVSS 5.5≥ 7.0.0.0, < 7.0.5.20≥ 7.1.0.0, < 7.1.2.16+6 more2024-02-06
CVE-2024-22331 [MEDIUM] CWE-200 CVE-2024-22331: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 thro
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971.
nvd
CVE-2020-4884P4MEDIUMCVSS 5.5v6.2.7.9v7.0.5.4+1 more2021-03-30
CVE-2020-4884 [MEDIUM] CWE-312 CVE-2020-4884: IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear t
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
nvd
CVE-2022-22367P4MEDIUMCVSS 5.5v6.2.7.15v7.0.5.10+2 more2022-07-01
CVE-2022-22367 [MEDIUM] CWE-312 CVE-2022-22367: IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive databas
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
nvd
CVE-2016-2994P4MEDIUMCVSS 5.4v6.2.0.0v6.2.0.1+4 more2016-12-01
CVE-2016-2994 [MEDIUM] CWE-79 CVE-2016-2994: Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote
Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-2941P4MEDIUMCVSS 5.5v6.0v6.0.1+40 more2017-02-01
CVE-2016-2941 [MEDIUM] CWE-200 CVE-2016-2941: IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive info
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
nvd
CVE-2022-43877P4MEDIUMCVSS 5.5≥ 6.2.0.0, < 6.2.7.20≥ 7.0.0.0, < 7.0.5.15+8 more2023-05-06
CVE-2022-43877 [MEDIUM] CWE-922 CVE-2022-43877: IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information duri
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.
nvd
CVE-2020-4944P4MEDIUMCVSS 5.5v7.0.3.0v7.0.4.0+6 more2021-03-30
CVE-2020-4944 [MEDIUM] CWE-312 CVE-2020-4944: IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
nvd
CVE-2025-1997P4MEDIUMCVSS 4.6≥ 7.0.0.0, < 7.0.5.26≥ 7.1.0.0, < 7.1.2.22+6 more2025-03-27
CVE-2025-1997 [MEDIUM] CWE-80 CVE-2025-1997: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1
is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
nvd
CVE-2015-7415P4MEDIUMCVSS 5.4v6.0v6.0.1.0+25 more2016-01-01
CVE-2015-7415 [MEDIUM] CWE-79 CVE-2015-7415: Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1
Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2024-22334P4MEDIUMCVSS 4.4≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+5 more2024-04-12
CVE-2024-22334 [MEDIUM] CWE-732 CVE-2024-22334: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated permissions of objects using that type ma
nvd
CVE-2023-42015P4MEDIUMCVSS 4.3≥ 7.1.0.0, < 7.1.2.15≥ 7.2.0.0, < 7.2.3.8+4 more2023-12-19
CVE-2023-42015 [MEDIUM] CWE-79 CVE-2023-42015: IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vul
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.
nvd
CVE-2024-22339P4MEDIUMCVSS 4.3≥ 7.0.0.0, < 7.0.5.21≥ 7.1.0.0, < 7.1.2.17+6 more2024-04-12
CVE-2024-22339 [MEDIUM] CWE-532 CVE-2024-22339: IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 thro
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM X-Force ID: 279979.
nvd
CVE-2022-46771P4MEDIUMCVSS 4.6≥ 6.2.0.0, ≤ 6.2.7.18≥ 7.0.5.0, ≤ 7.0.5.13+7 more2022-12-20
CVE-2022-46771 [MEDIUM] CWE-79 CVE-2022-46771: IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within
nvd
CVE-2021-29711P4MEDIUMCVSS 4.3v6.2.7.3v7.0.3.0+9 more2021-07-08
CVE-2021-29711 [MEDIUM] CVE-2021-29711: IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0,
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.
nvd
CVE-2025-36162P4MEDIUMCVSS 4.3≥ 8.1, ≤ 8.1.2.12025-09-02
CVE-2025-36162 [MEDIUM] CWE-497 CVE-2025-36162: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.
nvd
CVE-2016-0364P4MEDIUMCVSS 4.3v6.0v6.0.1.0+34 more2016-07-01
CVE-2016-0364 [MEDIUM] CWE-200 CVE-2016-0364: IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
nvd
CVE-2020-4484P4MEDIUMCVSS 4.3v6.2.7.3v6.2.7.4+2 more2020-11-06
CVE-2020-4484 [MEDIUM] CVE-2020-4484: IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive informati
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force ID: 181858.
nvd
CVE-2016-0373P4MEDIUMCVSS 4.3≥ 6.0, ≤ 6.2.2.1v6.1.0.2+41 more2018-08-30
CVE-2016-0373 [MEDIUM] CWE-285 CVE-2016-0373: IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive informa
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
nvd
CVE-2016-0320P4MEDIUMCVSS 4.3v6.0v6.0.1+40 more2017-02-01
CVE-2016-0320 [MEDIUM] CWE-284 CVE-2016-0320: IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST en
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
nvd
CVE-2023-42012P4MEDIUMCVSS 5.5≥ 7.2.0.0, ≤ 7.2.3.7≥ 7.3.0.0, ≤ 7.3.2.2+2 more2023-12-20
CVE-2023-42012 [MEDIUM] CWE-20 CVE-2023-42012: An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows se
An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509.
nvd