First published: Fri Sep 25 2020(Updated: )
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181857.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | =6.2.7.3 | |
IBM UrbanCode Deploy | =6.2.7.4 | |
IBM UrbanCode Deploy | =7.0.3.0 | |
IBM UrbanCode Deploy | =7.0.4.0 | |
IBM UCD - IBM UrbanCode Deploy | <=6.2.7.4 | |
IBM UCD - IBM UrbanCode Deploy | <=6.2.7.3 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0.4.0 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0.3.0 | |
IBM UCD - IBM UrbanCode Deploy | <=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4483 is a vulnerability in IBM UrbanCode Deploy (UCD) that could allow a remote attacker to obtain sensitive information.
CVE-2020-4483 allows a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser, which could be used in further attacks against the system.
IBM UrbanCode Deploy versions 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 are affected by CVE-2020-4483.
The severity of CVE-2020-4483 is medium with a CVSS score of 4.3.
To fix CVE-2020-4483, update IBM UrbanCode Deploy to a version that is not affected by the vulnerability.