PT-2018-4623 · Ibm · Ibm Urbancode Deploy

Published

2018-08-30

·

Updated

2019-10-09

·

CVE-2016-0373

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM UrbanCode Deploy versions 6.0 through 6.2.2.1
Description The issue allows an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data.
Recommendations For versions 6.0 through 6.2.2.1, consider restricting access to the UCD REST endpoints to minimize the risk of exploitation until a patch is available.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0373

Affected Products

Ibm Urbancode Deploy