First published: Mon Aug 13 2018(Updated: )
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | >6.1<=6.9.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1286 is a vulnerability in IBM UrbanCode Deploy 6.1 through 6.9.6.0 that allows a user with elevated permissions to obtain sensitive information about the server and database configuration.
CVE-2017-1286 has a severity rating of 6.5, which is considered medium.
An attacker with elevated permissions in the IBM UrbanCode Deploy UI can exploit CVE-2017-1286 to obtain sensitive configuration information even after their permissions have been revoked.
IBM UrbanCode Deploy versions 6.1 through 6.9.6.0 are affected by CVE-2017-1286.
Yes, IBM has released a fix for CVE-2017-1286. It is recommended to update to the latest version of IBM UrbanCode Deploy to mitigate this vulnerability.