Vulnerabilities > IBM > Urbancode Deploy > 6.2.7.4

DATE CVE VULNERABILITY TITLE RISK
2023-05-06 CVE-2022-43877 Insecure Storage of Sensitive Information vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file.
local
low complexity
ibm CWE-922
5.5
2022-12-20 CVE-2022-46771 Cross-site Scripting vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.6
2022-11-17 CVE-2022-40751 Insufficiently Protected Credentials vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches.  IBM X-Force ID:   236601.
network
low complexity
ibm CWE-522
4.9
2022-08-01 CVE-2022-35716 Incorrect Authorization vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
network
low complexity
ibm CWE-863
6.5
2022-04-27 CVE-2022-22315 Unspecified vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions.
network
low complexity
ibm
8.8
2020-11-06 CVE-2020-4484 Information Exposure vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system.
network
low complexity
ibm CWE-200
4.0
2020-11-06 CVE-2020-4483 Information Exposure Through an Error Message vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.0
2020-11-06 CVE-2020-4482 Unspecified vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security.
network
low complexity
ibm
4.0
2020-08-05 CVE-2020-4481 XML Entity Expansion vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-776
6.4
2020-04-23 CVE-2019-4668 Insufficiently Protected Credentials vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1