HTML Injection Vulnerability in IBM UrbanCode Deploy and DevOps Deploy Products
CVE-2024-51472

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
6 January 2025

What is CVE-2024-51472?

Certain versions of IBM UrbanCode Deploy and IBM DevOps Deploy are susceptible to an HTML injection vulnerability that allows users to embed arbitrary HTML tags within the Web UI. This capability could potentially lead to the exposure of sensitive information, as malicious users could craft input that misuses the web application's rendering capabilities, compromising the security of the application and its users.

Affected Version(s)

DevOps Deploy 8.0 <= 8.0.1.3

UrbanCode Deploy 7.2 <= 7.2.3.13

UrbanCode Deploy 7.3 <= 7.3.2.8

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.