CVE-2024-54176: IBM UrbanCode Deploy missing authentication
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
Other sources
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability associated with CVE-2024-54176?
CVE-2024-54176 allows an authenticated user to obtain sensitive information about other users due to missing authorization in IBM DevOps Deploy and IBM UrbanCode Deploy.
Which versions of IBM software are affected by CVE-2024-54176?
CVE-2024-54176 affects IBM DevOps Deploy versions 8.0 to 8.0.1.4 and 8.1 to 8.1.0.0, as well as IBM UrbanCode Deploy versions 7.0 through 7.3.2.
What might an attacker gain access to due to CVE-2024-54176?
An attacker could potentially gain access to sensitive information regarding other users on the system using CVE-2024-54176.
How can I mitigate the risks associated with CVE-2024-54176?
To mitigate CVE-2024-54176, ensure that users have proper authorization controls in place and apply the recommended patches from IBM.
Is there a patch available for CVE-2024-54176?
Yes, IBM has provided patches to address the issues related to CVE-2024-54176, which should be applied promptly to affected systems.