HTML Injection Vulnerability in IBM UrbanCode Deploy and DevOps Deploy Products
CVE-2024-51472
3.1LOW
What is CVE-2024-51472?
Certain versions of IBM UrbanCode Deploy and IBM DevOps Deploy are susceptible to an HTML injection vulnerability that allows users to embed arbitrary HTML tags within the Web UI. This capability could potentially lead to the exposure of sensitive information, as malicious users could craft input that misuses the web application's rendering capabilities, compromising the security of the application and its users.
Affected Version(s)
DevOps Deploy 8.0 <= 8.0.1.3
UrbanCode Deploy 7.2 <= 7.2.3.13
UrbanCode Deploy 7.3 <= 7.3.2.8
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published