CVE-2022-40751: IBM UrbanCode Deploy information disclosure
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches. IBM X-Force ID:
236601.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40751?
The severity of CVE-2022-40751 is medium with a severity value of 4.9.
What is IBM UrbanCode Deploy (UCD)?
IBM UrbanCode Deploy (UCD) is a software product that allows organizations to automate the deployment and release of applications.
Which versions of IBM UrbanCode Deploy are affected by CVE-2022-40751?
IBM UrbanCode Deploy (UCD) versions 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 are affected by CVE-2022-40751.
What is the impact of CVE-2022-40751?
CVE-2022-40751 could allow a user with administrative privileges to recover a previously saved credential for authentication.
How can I fix CVE-2022-40751?
IBM has released security fixes for the affected versions of IBM UrbanCode Deploy. It is recommended to apply the latest patches provided by IBM to mitigate the vulnerability.