PT-2024-10237 · Ibm · Ibm Devops Velocity +1

Published

2024-01-09

·

Updated

2025-08-14

·

CVE-2024-22349

CVSS v3.1
4.0
VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The affected software is IBM DevOps Velocity and IBM UrbanCode Velocity.

The versions of IBM DevOps Velocity that are affected are 5.0.0, and the versions of IBM UrbanCode Velocity that are affected are 4.0.0 through 4.0.25.

These versions allow web pages to be stored locally, which can then be read by another user on the system, potentially exposing sensitive information.

An exploit for this issue may be available, and it's worth noting that this issue could impact multiple users, given the nature of the software and its potential use in shared environments.

More information about this issue, including potential exploits, can be found at https://t.co/ucoKaUeeZW.

#IBMDevOpsVelocity #IBMUrbanCodeVelocity #LocalReadingOfWebPages #WebBrowserCache #SensitiveInformation #IBMVelocityProducts #DevOpsVelocity #UrbanCodeVelocity #SecurityRisk

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00617
CVE-2024-22349

Affected Products

Ibm Devops Velocity
Ibm Urbancode Velocity