CVE-2016-0320: Medium severity IBM UrbanCode Deploy vulnerability
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0320?
CVE-2016-0320 has a medium severity rating due to improper authorization in multiple REST endpoints.
How do I fix CVE-2016-0320?
To fix CVE-2016-0320, update IBM UrbanCode Deploy to a fixed version as recommended in the product documentation.
What versions are affected by CVE-2016-0320?
CVE-2016-0320 affects IBM UrbanCode Deploy versions 6.0, 6.0.1 through 6.0.1.14, and 6.1 up to 6.2.2.1.
Who can be impacted by CVE-2016-0320?
Authenticated users of IBM UrbanCode Deploy can be impacted by CVE-2016-0320 if they exploit improperly authorized REST endpoints.
What type of vulnerability is CVE-2016-0320?
CVE-2016-0320 is a type of authorization vulnerability that allows unauthorized modification of Ucd objects.