CVE-2020-4944: Medium severity ibm urbancode vulnerability
Published Mar 30, 2021
·Updated
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
Affected Software
8 affected components
IBM UrbanCode Deploy=7.0.3.0
IBM UrbanCode Deploy=7.0.4.0
IBM UrbanCode Deploy=7.0.5.3
IBM UrbanCode Deploy=7.0.5.4
IBM UrbanCode Deploy=7.1.0.0
IBM UrbanCode Deploy=7.1.1.0
IBM UrbanCode Deploy=7.1.1.1
IBM UrbanCode Deploy=7.1.1.2
Event History
Mar 30, 2021
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4944.
2
What is the severity level of CVE-2020-4944?
CVE-2020-4944 has a severity level of medium.
3
Which versions of IBM UrbanCode Deploy are affected by CVE-2020-4944?
IBM UrbanCode Deploy versions 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 are affected by CVE-2020-4944.
4
How does CVE-2020-4944 exploit work?
CVE-2020-4944 exploits the storage of keystore passwords in plain text after a manual edit, which can then be read by a local user.
5
Is there a fix available for CVE-2020-4944?
Yes, a fix is available for CVE-2020-4944. Please refer to the IBM support page for more information.