CVE-2025-36162: IBM DevOps Deploy / IBM UrbanCode Deploy information disclosure
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.
Other sources
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1.x before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36162?
CVE-2025-36162 has been rated as a moderate severity vulnerability due to the potential for authenticated users to access sensitive configuration information.
How do I fix CVE-2025-36162?
To resolve CVE-2025-36162, update IBM UrbanCode Deploy to version 8.1.2.2 or later.
Who is affected by CVE-2025-36162?
CVE-2025-36162 affects IBM UrbanCode Deploy versions prior to 8.1.2.2.
What type of information can be leaked due to CVE-2025-36162?
CVE-2025-36162 allows authenticated users to access sensitive configuration information on the system.
Is CVE-2025-36162 applicable to all users of IBM UrbanCode Deploy?
CVE-2025-36162 specifically impacts authenticated users of IBM UrbanCode Deploy versions 8.1 to 8.1.2.1.