CVE-2014-6074: Medium severity ibm urbancode vulnerability
Published Sep 10, 2014
·Updated
IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.
Affected Software
1 affected component
IBM UrbanCode Deploy=6.1.0.2
Remediation
Patch Available
Event History
Sep 10, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6074?
CVE-2014-6074 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-6074?
To fix CVE-2014-6074, upgrade IBM UrbanCode Deploy to version 6.1.0.2 IF1 or later.
3
Who is impacted by CVE-2014-6074?
CVE-2014-6074 affects IBM UrbanCode Deploy versions prior to IF1.
4
What type of vulnerability is CVE-2014-6074?
CVE-2014-6074 is a security vulnerability that allows remote authenticated users to access keystore secret keys.
5
Can CVE-2014-6074 be exploited remotely?
Yes, CVE-2014-6074 can be exploited by remote authenticated users via direct requests to a specific UI page.