CVE-2015-4964: Medium severity ibm urbancode vulnerability
Published Oct 5, 2015
·Updated
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTHTOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
Affected Software
20 affected components
IBM UrbanCode Deploy=6.0
IBM UrbanCode Deploy=6.0.1.0
IBM UrbanCode Deploy=6.0.1.1
IBM UrbanCode Deploy=6.0.1.2
IBM UrbanCode Deploy=6.0.1.3
IBM UrbanCode Deploy=6.0.1.4
IBM UrbanCode Deploy=6.0.1.5
IBM UrbanCode Deploy=6.0.1.6
IBM UrbanCode Deploy=6.0.1.7
IBM UrbanCode Deploy=6.0.1.8
IBM UrbanCode Deploy=6.0.1.9
IBM UrbanCode Deploy=6.1.1.0
IBM UrbanCode Deploy=6.1.1.1
IBM UrbanCode Deploy=6.1.1.2
IBM UrbanCode Deploy=6.1.1.3
IBM UrbanCode Deploy=6.1.1.4
IBM UrbanCode Deploy=6.1.1.5
IBM UrbanCode Deploy=6.1.1.6
IBM UrbanCode Deploy=6.1.1.7
IBM UrbanCode Deploy=6.1.2
Remediation
Patch Available
Event History
Oct 5, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4964?
CVE-2015-4964 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2015-4964?
To fix CVE-2015-4964, upgrade IBM UrbanCode Deploy to versions 6.0.1.10, 6.1.1.8, or 6.1.2 and above.
3
What impact does CVE-2015-4964 have on IBM UrbanCode Deploy?
CVE-2015-4964 allows remote authenticated users to gain privileges through admin AUTH_TOKEN values written in execution logs.
4
Which versions of IBM UrbanCode Deploy are affected by CVE-2015-4964?
CVE-2015-4964 affects IBM UrbanCode Deploy versions 6.0, 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2.
5
Is CVE-2015-4964 a remote exploit vulnerability?
Yes, CVE-2015-4964 can be exploited remotely by authenticated users.