First published: Wed Jun 29 2016(Updated: )
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | =6.0 | |
IBM UrbanCode Deploy | =6.0.1.0 | |
IBM UrbanCode Deploy | =6.0.1.1 | |
IBM UrbanCode Deploy | =6.0.1.2 | |
IBM UrbanCode Deploy | =6.0.1.3 | |
IBM UrbanCode Deploy | =6.0.1.4 | |
IBM UrbanCode Deploy | =6.0.1.5 | |
IBM UrbanCode Deploy | =6.0.1.6 | |
IBM UrbanCode Deploy | =6.0.1.7 | |
IBM UrbanCode Deploy | =6.0.1.8 | |
IBM UrbanCode Deploy | =6.0.1.9 | |
IBM UrbanCode Deploy | =6.0.1.10 | |
IBM UrbanCode Deploy | =6.0.1.11 | |
IBM UrbanCode Deploy | =6.0.1.12 | |
IBM UrbanCode Deploy | =6.1 | |
IBM UrbanCode Deploy | =6.1.0.1 | |
IBM UrbanCode Deploy | =6.1.0.2 | |
IBM UrbanCode Deploy | =6.1.0.3 | |
IBM UrbanCode Deploy | =6.1.0.4 | |
IBM UrbanCode Deploy | =6.1.1.0 | |
IBM UrbanCode Deploy | =6.1.1.1 | |
IBM UrbanCode Deploy | =6.1.1.2 | |
IBM UrbanCode Deploy | =6.1.1.3 | |
IBM UrbanCode Deploy | =6.1.1.4 | |
IBM UrbanCode Deploy | =6.1.1.5 | |
IBM UrbanCode Deploy | =6.1.1.6 | |
IBM UrbanCode Deploy | =6.1.1.7 | |
IBM UrbanCode Deploy | =6.1.1.8 | |
IBM UrbanCode Deploy | =6.1.2 | |
IBM UrbanCode Deploy | =6.1.3 | |
IBM UrbanCode Deploy | =6.1.3.1 | |
IBM UrbanCode Deploy | =6.1.3.2 | |
IBM UrbanCode Deploy | =6.2.0.0 | |
IBM UrbanCode Deploy | =6.2.0.1 | |
IBM UrbanCode Deploy | =6.2.0.2 | |
IBM UrbanCode Deploy | =6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0267 is classified as a medium severity vulnerability that allows remote authenticated users to gain access to sensitive information.
To mitigate CVE-2016-0267, upgrade IBM UrbanCode Deploy to version 6.0.1.13 or higher, 6.1.3.3 or higher, or 6.2.1.1 or higher.
CVE-2016-0267 affects IBM UrbanCode Deploy versions 6.0.x prior to 6.0.1.13, 6.1.x prior to 6.1.3.3, and 6.2.x prior to 6.2.1.1.
CVE-2016-0267 can expose sensitive cleartext secure-property information if exploited.
The responsibility for addressing CVE-2016-0267 lies with the users and administrators of IBM UrbanCode Deploy, who must apply the necessary updates.