First published: Wed Sep 10 2014(Updated: )
IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode | =6.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6074 is classified as a medium severity vulnerability.
To fix CVE-2014-6074, upgrade IBM UrbanCode Deploy to version 6.1.0.2 IF1 or later.
CVE-2014-6074 affects IBM UrbanCode Deploy versions prior to IF1.
CVE-2014-6074 is a security vulnerability that allows remote authenticated users to access keystore secret keys.
Yes, CVE-2014-6074 can be exploited by remote authenticated users via direct requests to a specific UI page.