First published: Wed Dec 04 2024(Updated: )
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UCD - IBM UrbanCode Deploy | <=7.2 - 7.2.3.13 | |
IBM UCD - IBM UrbanCode Deploy | <=7.3 - 7.3.2.8 | |
IBM UCD - IBM DevOps Deploy | <=8.0 - 8.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51472 is classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
To fix CVE-2024-51472, update IBM UrbanCode Deploy to version 7.2.3.14 or above, or 7.3.2.9 or above, or 8.0.1.4 or above.
CVE-2024-51472 affects IBM UrbanCode Deploy versions 7.2 through 7.2.3.13 and versions 7.3 through 7.3.2.8.
CVE-2024-51472 is an HTML injection vulnerability that allows arbitrary HTML embedding in the Web UI.
The potential impact of CVE-2024-51472 includes the disclosure of sensitive information through manipulated content in the Web UI.