CVE-2022-22367: Medium severity ibm urbancode deploy vulnerability
Published Jun 20, 2022
·Updated
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
Other sources
IBM UrbanCode Deploy (UCD) could disclose sensitive database information to a local user in plain text.
Affected Software
8 affected components
IBM UCD - IBM UrbanCode Deploy<=7.2.0.0 - 7.2.2.1
IBM UCD - IBM UrbanCode Deploy<=7.1.0.0 - 7.1.2.6
IBM UCD - IBM UrbanCode Deploy<=7.0.0.0 - 7.0.5.10
IBM UCD - IBM UrbanCode Deploy<=6.0.0.0 - 6.2.7.15
IBM UrbanCode Deploy=6.2.7.15
IBM UrbanCode Deploy=7.0.5.10
IBM UrbanCode Deploy=7.1.2.6
IBM UrbanCode Deploy=7.2.2.1
Remediation
Patch Available
Event History
Jun 20, 2022
CVE Published
via IBM·12:00 AM
Jul 1, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22367.
2
What software is affected by this vulnerability?
IBM UrbanCode Deploy (UCD) versions 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 are affected by this vulnerability.
3
What is the severity of CVE-2022-22367?
CVE-2022-22367 has a severity rating of 5.5 (medium).
4
How could this vulnerability be exploited?
This vulnerability could be exploited by a local user to disclose sensitive database information in plain text.
5
What is the recommended solution for this vulnerability?
IBM has provided a fix for this vulnerability. Users should update to the latest version of IBM UrbanCode Deploy.