First published: Thu Mar 30 2023(Updated: )
IBM UrbanCode Deploy information disclosure
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode | ||
IBM UrbanCode | <=6.2 | |
IBM UrbanCode | <=7.0 | |
IBM UrbanCode | <=7.1 | |
IBM UrbanCode | <=6.2.7.19 | |
IBM UrbanCode | <=7.0.5.14 | |
IBM UrbanCode | <=7.1.2.10 | |
IBM UrbanCode | <=7.2 | |
IBM UrbanCode | <=7.2.3.3 | |
IBM UrbanCode | <=7.3 | |
IBM UrbanCode | <=7.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability IBM-XFORCE-240148 has a medium severity due to potential information disclosure of sensitive password information.
To resolve IBM-XFORCE-240148, update IBM UrbanCode Deploy to the latest version where the vulnerability has been addressed.
IBM-XFORCE-240148 affects IBM UrbanCode Deploy versions up to and including 7.3.0.1.
IBM-XFORCE-240148 may disclose sensitive password information during the manual editing of the agentrelay.properties file.
A recommended temporary measure for IBM-XFORCE-240148 is to limit access to the agentrelay.properties file to prevent unauthorized viewing.