CVE-2016-0364: Infoleak
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0364?
CVE-2016-0364 is classified as a medium severity vulnerability.
How do I fix CVE-2016-0364?
To fix CVE-2016-0364, update your IBM UrbanCode Deploy to version 6.0.1.13, 6.1.3.3, or 6.2.1.1 or later.
What impact does CVE-2016-0364 have on my system?
CVE-2016-0364 allows remote authenticated users to gain access to sensitive information due to inadequate logging obfuscation.
Which versions of IBM UrbanCode Deploy are affected by CVE-2016-0364?
CVE-2016-0364 affects IBM UrbanCode Deploy versions prior to 6.0.1.13, 6.1.3.3, and 6.2.1.1.
Who is impacted by the CVE-2016-0364 vulnerability?
Organizations using vulnerable versions of IBM UrbanCode Deploy are at risk of exposure to sensitive information.