CVE-2020-4884: Medium severity ibm urbancode deploy vulnerability
Published Mar 29, 2021
·Updated
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
Other sources
IBM UrbanCode Deploy (UCD) stores user credentials in plain in clear text which can be read by a local user.
Affected Software
7 affected components
IBM UCD - IBM UrbanCode Deploy<=7.1.1.1
IBM UCD - IBM UrbanCode Deploy<=7.0.5.4
IBM UCD - IBM UrbanCode Deploy<=6.2.7.9
IBM UCD - IBM UrbanCode Deploy<=All
IBM UrbanCode Deploy=6.2.7.9
IBM UrbanCode Deploy=7.0.5.4
IBM UrbanCode Deploy=7.1.1.1
Event History
Mar 29, 2021
CVE Published
via IBM·12:00 AM
Mar 30, 2021
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4884.
2
What is the severity level of CVE-2020-4884?
The severity level of CVE-2020-4884 is medium.
3
Which products are affected by CVE-2020-4884?
IBM UrbanCode Deploy 6.2.7.9, 7.0.5.4, and 7.1.1.1 are affected by CVE-2020-4884.
4
How does CVE-2020-4884 impact user credentials?
CVE-2020-4884 allows a local user to read user credentials in plain text stored by IBM UrbanCode Deploy.
5
How can I fix the vulnerability CVE-2020-4884?
To fix CVE-2020-4884, upgrade to a fixed version of IBM UrbanCode Deploy.