First published: Thu Apr 11 2024(Updated: )
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated permissions of objects using that type may not be fully revoked. This could lead to incorrect reporting of permission configuration and unexpected privileges being retained. IBM X-Force ID: 279974.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UCD - IBM UrbanCode Deploy | <=7.0 - 7.0.5.20 | |
IBM UCD - IBM UrbanCode Deploy | <=7.1 - 7.1.2.16 | |
IBM UCD - IBM UrbanCode Deploy | <=7.2 - 7.2.3.9 | |
IBM UCD - IBM UrbanCode Deploy | <=7.3 - 7.3.2.4 | |
IBM UCD - IBM DevOps Deploy | <=8.0 - 8.0.0.1 | |
IBM DevOps Deploy | >=8.0.0.0<8.0.1.0 | |
IBM UrbanCode Deploy | >=7.0.0.0<7.0.5.21 | |
IBM UrbanCode Deploy | >=7.1.0.0<7.1.2.17 | |
IBM UrbanCode Deploy | >=7.2.0.0<7.2.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22334 is currently rated as high due to potential unauthorized access risks.
To mitigate CVE-2024-22334, upgrade to the latest patched version of IBM UrbanCode Deploy and IBM DevOps Deploy.
CVE-2024-22334 affects IBM UrbanCode Deploy versions 7.0 through 7.3.2.4 and IBM DevOps Deploy version 8.0.0.1.
CVE-2024-22334 could lead to incomplete revocation of permissions, allowing unauthorized access to security resources.
No specific workarounds are recommended, and patching to a secure version is advised for CVE-2024-22334.