CVE-2022-22366: Medium severity ibm urbancode deploy vulnerability
Published Jun 20, 2022
·Updated
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.
Other sources
IBM UrbanCode Deploy (UCD) stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
8 affected components
IBM UCD - IBM UrbanCode Deploy<=7.2.0.0 - 7.2.2.1
IBM UCD - IBM UrbanCode Deploy<=7.1.0.0 - 7.1.2.6
IBM UCD - IBM UrbanCode Deploy<=7.0.0.0 - 7.0.5.10
IBM UCD - IBM UrbanCode Deploy<=6.0.0.0 - 6.2.7.15
IBM UrbanCode Deploy=6.2.7.15
IBM UrbanCode Deploy=7.0.5.10
IBM UrbanCode Deploy=7.1.2.6
IBM UrbanCode Deploy=7.2.2.1
Remediation
Patch Available
Event History
Jun 20, 2022
CVE Published
via IBM·12:00 AM
Jul 1, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM UrbanCode Deploy issue?
The vulnerability ID for this IBM UrbanCode Deploy issue is CVE-2022-22366.
2
What is the severity rating of CVE-2022-22366?
CVE-2022-22366 has a severity rating of 4.9, which is considered medium.
3
Which versions of IBM UrbanCode Deploy are affected?
IBM UrbanCode Deploy versions 6.2.7.15 to 7.2.2.1 are affected by this vulnerability.
4
How does this vulnerability impact user credentials?
This vulnerability allows a local user to read user credentials stored in plain clear text.
5
Is there a fix available for this vulnerability?
Yes, IBM has provided fixes for the affected versions of IBM UrbanCode Deploy. Please refer to the official IBM support page for more details.