First published: Tue Apr 21 2020(Updated: )
IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the server is configured to enable Distributed Front End (DFE). IBM X-Force ID: 174955.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | >=7.0.3.0<7.0.3.4 | |
IBM UrbanCode Deploy | >=7.0.4.0<7.0.4.3 | |
<=7.0.3.0 | ||
<=7.0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4202.
The severity of CVE-2020-4202 is high.
IBM UrbanCode Deploy (UCD) versions 7.0.3.0 and 7.0.4.0 are affected by CVE-2020-4202.
An authenticated user can impersonate another user if the IBM UrbanCode Deploy server is configured to enable Distributed Front End (DFE).
You can find more information about CVE-2020-4202 at the IBM X-Force ID: 174955 and the IBM Support page.