First published: Mon Jun 20 2022(Updated: )
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | =6.2.7.15 | |
IBM UrbanCode Deploy | =7.0.5.10 | |
IBM UrbanCode Deploy | =7.1.2.6 | |
IBM UrbanCode Deploy | =7.2.2.1 | |
<=7.2.0.0 - 7.2.2.1 | ||
<=7.1.0.0 - 7.1.2.6 | ||
<=7.0.0.0 - 7.0.5.10 | ||
<=6.0.0.0 - 6.2.7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM UrbanCode Deploy issue is CVE-2022-22366.
CVE-2022-22366 has a severity rating of 4.9, which is considered medium.
IBM UrbanCode Deploy versions 6.2.7.15 to 7.2.2.1 are affected by this vulnerability.
This vulnerability allows a local user to read user credentials stored in plain clear text.
Yes, IBM has provided fixes for the affected versions of IBM UrbanCode Deploy. Please refer to the official IBM support page for more details.