First published: Wed Mar 08 2023(Updated: )
IBM UrbanCode Deploy (UCD) could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Deploy | <=6.2 | |
IBM UrbanCode Deploy | <=7.0 | |
IBM UrbanCode Deploy | <=7.1 | |
IBM UrbanCode Deploy | <=6.2.7.19 | |
IBM UrbanCode Deploy | <=7.0.5.14 | |
IBM UrbanCode Deploy | <=7.1.2.10 | |
IBM UrbanCode Deploy | <=7.2 | |
IBM UrbanCode Deploy | <=7.2.3.3 | |
IBM UrbanCode Deploy | <=7.3 | |
IBM UrbanCode Deploy | <=7.3.0.1 | |
IBM UrbanCode Deploy | >=6.2.0.0<6.2.7.20 | |
IBM UrbanCode Deploy | >=7.0.0.0<7.0.5.15 | |
IBM UrbanCode Deploy | >=7.1.0.0<7.1.2.11 | |
IBM UrbanCode Deploy | >=7.2.0.0<7.2.3.4 | |
IBM UrbanCode Deploy | >=7.3.0.0<7.3.1.0 | |
IBM UCD - IBM UrbanCode Deploy | <=6.2 - 6.2.7.19 | |
IBM UCD - IBM UrbanCode Deploy | <=7.0 - 7.0.5.14 | |
IBM UCD - IBM UrbanCode Deploy | <=7.1 - 7.1.2.10 | |
IBM UCD - IBM UrbanCode Deploy | <=7.2 - 7.2.3.3 | |
IBM UCD - IBM UrbanCode Deploy | <=7.3 - 7.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file.
The severity of IBM UrbanCode Deploy information disclosure vulnerability (CVE-2022-43877) is medium with a severity value of 5.1.
IBM UrbanCode Deploy versions up to 7.3.0.1 are affected by the information disclosure vulnerability (CVE-2022-43877).
The vulnerability can be exploited by manually editing the agentrelay.properties file, which can expose sensitive password information.
Yes, you can find more information about the vulnerability on the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/240148), [link2](https://www.ibm.com/support/pages/node/6967351), [link3](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43877).