CVE-2025-1998: IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosure
IBM UrbanCode Deploy (UCD) stores potentially sensitive authentication token information in log files that could be read by a local user.
Other sources
IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1
stores potentially sensitive authentication token information in log files that could be read by a local user.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1998?
CVE-2025-1998 is classified as a medium severity vulnerability due to the exposure of sensitive authentication tokens in log files.
How can I mitigate CVE-2025-1998?
To mitigate CVE-2025-1998, ensure that log files are properly secured and limit access to authorized users only.
What versions are affected by CVE-2025-1998?
CVE-2025-1998 affects IBM UrbanCode Deploy versions up to 7.1.2.21, 7.2 up to 7.2.3.14, 7.3 up to 7.3.2.9, and IBM DevOps Deploy versions up to 8.0.1.4.
Who is impacted by CVE-2025-1998?
Any organization using affected versions of IBM UrbanCode Deploy or IBM DevOps Deploy may be impacted by CVE-2025-1998.
Is there an update available for CVE-2025-1998?
Yes, users should check for the latest updates from IBM to remediate CVE-2025-1998 and secure their systems.