Sensitive Information Disclosure in IBM UrbanCode Deploy
CVE-2022-35716

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 August 2022

Summary

IBM UrbanCode Deploy versions from 6.2.0.0 to 7.2.3.0 are affected by a vulnerability that may allow authenticated users to gain access to sensitive information due to inadequate security checks in place. This flaw poses a risk of data exposure within the system, potentially affecting user confidentiality. The identified issue highlights the need for stricter security measures to safeguard sensitive data against unauthorized access.

Affected Version(s)

UrbanCode Deploy 7.0.0.0

UrbanCode Deploy 7.1.0.0

UrbanCode Deploy 7.2.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.