PT-2018-4623 · Ibm · Ibm Urbancode Deploy
Publicado
2018-08-30
·
Atualizado
2019-10-09
·
CVE-2016-0373
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM UrbanCode Deploy versions 6.0 through 6.2.2.1
Description
The issue allows an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data.
Recommendations
For versions 6.0 through 6.2.2.1, consider restricting access to the UCD REST endpoints to minimize the risk of exploitation until a patch is available.
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Urbancode Deploy