Show filters
59 Total Results
Displaying 11-20 of 59
Sort by:
Attacker Value
Unknown
CVE-2023-47161
Disclosure Date: December 20, 2023 (last updated December 28, 2023)
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. IBM X-Force ID: 270799.
0
Attacker Value
Unknown
CVE-2023-42013
Disclosure Date: December 20, 2023 (last updated December 28, 2023)
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510.
0
Attacker Value
Unknown
CVE-2023-42012
Disclosure Date: December 20, 2023 (last updated December 28, 2023)
An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509.
0
Attacker Value
Unknown
CVE-2023-42015
Disclosure Date: December 19, 2023 (last updated December 28, 2023)
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.
0
Attacker Value
Unknown
CVE-2023-40376
Disclosure Date: October 04, 2023 (last updated October 09, 2023)
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.
0
Attacker Value
Unknown
CVE-2022-43877
Disclosure Date: May 06, 2023 (last updated January 30, 2025)
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.
0
Attacker Value
Unknown
CVE-2022-46771
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 242273.
0
Attacker Value
Unknown
CVE-2022-40751
Disclosure Date: November 17, 2022 (last updated November 08, 2023)
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID:
236601.
0
Attacker Value
Unknown
CVE-2022-35716
Disclosure Date: July 29, 2022 (last updated October 08, 2023)
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.
0
Attacker Value
Unknown
CVE-2022-22367
Disclosure Date: June 30, 2022 (last updated October 07, 2023)
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
0