CVE-2024-56469: IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authentication
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Other sources
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56469?
CVE-2024-56469 has been classified as a medium-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-56469?
To mitigate CVE-2024-56469, ensure that agent authentication is properly configured in IBM UrbanCode Deploy's Agent Relay service.
Which versions of IBM UrbanCode Deploy are affected by CVE-2024-56469?
CVE-2024-56469 affects IBM UrbanCode Deploy versions 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10.
What type of vulnerability is CVE-2024-56469?
CVE-2024-56469 is an authentication vulnerability that could lead to unauthorized access and data exposure.
Who should be concerned about CVE-2024-56469?
Organizations using affected versions of IBM UrbanCode Deploy should prioritize addressing CVE-2024-56469 to protect sensitive data.