First published: Mon Oct 17 2022(Updated: )
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID: 236601.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | >=6.2.7.0<6.2.7.18 | |
IBM UrbanCode Deploy | >=7.0.0.0<7.0.5.13 | |
IBM UrbanCode Deploy | >=7.1.0.0<7.1.2.9 | |
IBM UrbanCode Deploy | >=7.2.0.0<7.2.3.2 | |
IBM UCD - IBM UrbanCode Deploy | <=6.2.7.0 - 6.2.7.17 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0.0.0 - 7.0.5.12 | |
IBM UCD - IBM UrbanCode Deploy | <=7.1.0.0 - 7.1.2.8 | |
IBM UCD - IBM UrbanCode Deploy | <=7.2.0.0 - 7.2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40751 is medium with a severity value of 4.9.
IBM UrbanCode Deploy (UCD) is a software product that allows organizations to automate the deployment and release of applications.
IBM UrbanCode Deploy (UCD) versions 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 are affected by CVE-2022-40751.
CVE-2022-40751 could allow a user with administrative privileges to recover a previously saved credential for authentication.
IBM has released security fixes for the affected versions of IBM UrbanCode Deploy. It is recommended to apply the latest patches provided by IBM to mitigate the vulnerability.