CVE-2017-1286: Infoleak
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1286?
CVE-2017-1286 is a vulnerability in IBM UrbanCode Deploy 6.1 through 6.9.6.0 that allows a user with elevated permissions to obtain sensitive information about the server and database configuration.
What is the severity of CVE-2017-1286?
CVE-2017-1286 has a severity rating of 6.5, which is considered medium.
How can an attacker exploit CVE-2017-1286?
An attacker with elevated permissions in the IBM UrbanCode Deploy UI can exploit CVE-2017-1286 to obtain sensitive configuration information even after their permissions have been revoked.
Which versions of IBM UrbanCode Deploy are affected by CVE-2017-1286?
IBM UrbanCode Deploy versions 6.1 through 6.9.6.0 are affected by CVE-2017-1286.
Is there a fix available for CVE-2017-1286?
Yes, IBM has released a fix for CVE-2017-1286. It is recommended to update to the latest version of IBM UrbanCode Deploy to mitigate this vulnerability.