CVE-2023-40376: IBM UrbanCode Deploy (UCD) improper authentication controls
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.
Other sources
IBM UrbanCode Deploy (UCD) under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM UrbanCode Deploy vulnerability?
The vulnerability ID for this IBM UrbanCode Deploy vulnerability is CVE-2023-40376.
What is the severity of CVE-2023-40376?
The severity of CVE-2023-40376 is medium, with a severity value of 6.5.
How does this vulnerability affect IBM UrbanCode Deploy?
This vulnerability affects IBM UrbanCode Deploy versions 7.1 - 7.1.2.12, 7.2 - 7.2.3.5, and 7.3 - 7.3.2.0 under certain configurations.
What is the risk of this vulnerability?
This vulnerability allows an authenticated user to make changes to environment variables due to improper authentication controls.
Is there a fix available for this vulnerability?
Yes, there is a fix available for this vulnerability. Please refer to the IBM support pages for more information.