CVE-2025-1997: IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy HTML injection
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Other sources
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1
is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1997?
CVE-2025-1997 has a severity rating that suggests it could lead to potential sensitive information disclosure due to HTML injection.
How do I fix CVE-2025-1997?
To fix CVE-2025-1997, upgrade IBM UrbanCode Deploy to versions 7.0.5.26, 7.1.2.3, 7.2.3.15, 7.3.2.10, or 8.0.1.5 or higher.
Which versions of IBM UrbanCode Deploy are affected by CVE-2025-1997?
CVE-2025-1997 affects IBM UrbanCode Deploy versions 7.0 through 7.0.5.25, 7.1 through 7.1.2.2, 7.2 through 7.2.3.14, 7.3 through 7.3.2.9, and 8.0 through 8.0.1.4.
What type of vulnerability is CVE-2025-1997?
CVE-2025-1997 is an HTML injection vulnerability that allows users to embed arbitrary HTML in the Web UI.
Can CVE-2025-1997 lead to data breaches?
Yes, CVE-2025-1997 can potentially lead to sensitive information disclosure, making it a security risk for users.