IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/112119 | VDB Entry Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/112119 | VDB Entry Vendor Advisory |
Configurations
History
21 Nov 2024, 02:41
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 3.1 |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/112119 - VDB Entry, Vendor Advisory |
Information
Published : 2018-08-30 16:29
Updated : 2024-11-21 02:41
NVD link : CVE-2016-0373
Mitre link : CVE-2016-0373
CVE.ORG link : CVE-2016-0373
JSON object : View
Products Affected
ibm
- urbancode_deploy
CWE
CWE-285
Improper Authorization