CVE-2016-0267: Infoleak
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0267?
CVE-2016-0267 is classified as a medium severity vulnerability that allows remote authenticated users to gain access to sensitive information.
How do I fix CVE-2016-0267?
To mitigate CVE-2016-0267, upgrade IBM UrbanCode Deploy to version 6.0.1.13 or higher, 6.1.3.3 or higher, or 6.2.1.1 or higher.
What versions of IBM UrbanCode Deploy are affected by CVE-2016-0267?
CVE-2016-0267 affects IBM UrbanCode Deploy versions 6.0.x prior to 6.0.1.13, 6.1.x prior to 6.1.3.3, and 6.2.x prior to 6.2.1.1.
What kind of information can be exposed due to CVE-2016-0267?
CVE-2016-0267 can expose sensitive cleartext secure-property information if exploited.
Who is responsible for addressing CVE-2016-0267 in IBM UrbanCode Deploy?
The responsibility for addressing CVE-2016-0267 lies with the users and administrators of IBM UrbanCode Deploy, who must apply the necessary updates.