CVE-2024-22349: IBM UrbanCode Velocity information disclosure
Published Oct 9, 2024
·Updated
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
Other sources
IBM UCV - UrbanCode Velocity allows web pages to be stored locally which can be read by another user on the system.
— IBM
Affected Software
4 affected components
IBM UrbanCode Velocity<=4.0.0 - 4.0.15
IBM DevOps Velocity<=5.0.0
hcltech Devops Velocity=5.0.0
IBM UrbanCode Velocity>=4.0.0<=4.0.15
Event History
Oct 9, 2024
CVE Published
via IBM·12:00 AM
Jan 20, 2025
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22349?
CVE-2024-22349 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2024-22349?
To fix CVE-2024-22349, update IBM UrbanCode Velocity to version 4.0.16 or higher and IBM DevOps Velocity to version 5.0.1 or higher.
3
What versions are affected by CVE-2024-22349?
CVE-2024-22349 affects IBM UrbanCode Velocity versions 4.0.0 to 4.0.15 and IBM DevOps Velocity version 5.0.0.
4
What type of vulnerability is CVE-2024-22349?
CVE-2024-22349 is a local information disclosure vulnerability.
5
Can CVE-2024-22349 be exploited remotely?
No, CVE-2024-22349 requires local access to the affected system for exploitation.