Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2024-55904

Disclosure Date: February 14, 2025 (last updated February 14, 2025)
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
Attacker Value
Unknown

CVE-2024-54176

Disclosure Date: February 08, 2025 (last updated February 09, 2025)
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
Attacker Value
Unknown

CVE-2024-51472

Disclosure Date: January 06, 2025 (last updated January 07, 2025)
IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Attacker Value
Unknown

CVE-2024-42195

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
0
Attacker Value
Unknown

CVE-2024-28781

Disclosure Date: May 14, 2024 (last updated January 28, 2025)
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285654.
Attacker Value
Unknown

CVE-2024-23561

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
0
Attacker Value
Unknown

CVE-2024-23558

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
0
Attacker Value
Unknown

CVE-2024-23560

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
0
Attacker Value
Unknown

CVE-2024-23559

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
0
Attacker Value
Unknown

CVE-2024-22359

Disclosure Date: April 12, 2024 (last updated January 30, 2025)
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.