CVE-2024-22347: IBM UrbanCode Velocity information disclosure
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM UCV - UrbanCode Velocity uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22347?
CVE-2024-22347 has a high severity level due to the potential exposure of highly sensitive information.
How do I fix CVE-2024-22347?
To mitigate CVE-2024-22347, it is recommended to upgrade IBM UrbanCode Velocity to a version higher than 4.0.15 or IBM DevOps Velocity to a version higher than 5.0.0.
What kind of cryptographic weaknesses does CVE-2024-22347 involve?
CVE-2024-22347 involves the use of weaker than expected cryptographic algorithms that could allow unauthorized decryption of sensitive data.
Which versions of IBM software are affected by CVE-2024-22347?
CVE-2024-22347 affects IBM UrbanCode Velocity versions 4.0.0 to 4.0.15 and IBM DevOps Velocity version 5.0.0.
Is there any impact on data security related to CVE-2024-22347?
Yes, CVE-2024-22347 poses a serious risk to data security as it could allow attackers to decrypt sensitive information.