PT-2020-18091 · Ibm · Ibm Urbancode Deploy

Published

2020-11-06

·

Updated

2022-07-12

·

CVE-2020-4482

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM UrbanCode Deploy versions 6.2.7.3 through 6.2.7.4 IBM UrbanCode Deploy versions 7.0.3.0 through 7.0.4.0
Description The issue allows an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls.
Recommendations For versions 6.2.7.3 and 6.2.7.4, consider restricting access to direct rest calls until a patch is available. For versions 7.0.3.0 and 7.0.4.0, consider restricting access to direct rest calls until a patch is available. As a temporary workaround, consider disabling direct rest calls to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-4482

Affected Products

Ibm Urbancode Deploy