CVE-2019-4667: Medium severity ibm urbancode deploy vulnerability
IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 171249.
Other sources
IBM UrbanCode Deploy (UCD) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-4667?
CVE-2019-4667 is a vulnerability in IBM UrbanCode Deploy (UCD) 7.0.5.2 that could allow a remote attacker to obtain sensitive information.
How does CVE-2019-4667 affect IBM UrbanCode Deploy?
CVE-2019-4667 affects IBM UrbanCode Deploy version 7.0.5.2.
What is the severity of CVE-2019-4667?
CVE-2019-4667 has a severity level of medium, with a CVSS score of 5.9.
How can an attacker exploit CVE-2019-4667?
An attacker can exploit CVE-2019-4667 by using man-in-the-middle techniques to obtain sensitive information.
Is there a fix for CVE-2019-4667?
To fix CVE-2019-4667, users should enable HTTP Strict Transport Security (HSTS) properly in IBM UrbanCode Deploy.