First published: Fri Sep 25 2020(Updated: )
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls. IBM X-Force ID: 181856.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UCD - IBM UrbanCode Deploy | <=6.2.7.4 | |
IBM UCD - IBM UrbanCode Deploy | <=6.2.7.3 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0.4.0 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0.3.0 | |
IBM UCD - IBM UrbanCode Deploy | <=All | |
IBM UrbanCode Deploy | =6.2.7.3 | |
IBM UrbanCode Deploy | =6.2.7.4 | |
IBM UrbanCode Deploy | =7.0.3.0 | |
IBM UrbanCode Deploy | =7.0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM UrbanCode Deploy vulnerability is CVE-2020-4482.
The severity of CVE-2020-4482 is medium.
The versions 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 of IBM UrbanCode Deploy are affected by CVE-2020-4482.
CVE-2020-4482 allows an authenticated user to bypass security in IBM UrbanCode Deploy by applying unauthorized additional statuses via direct REST calls.
You can find more information about CVE-2020-4482 on the IBM X-Force ID: 181856.