Lucene search

K
cveIbmCVE-2024-22358
HistoryApr 12, 2024 - 5:17 p.m.

CVE-2024-22358

2024-04-1217:17:22
CWE-613
ibm
web.nvd.nist.gov
35
ibm
urbancode deploy
session
impersonation
vulnerability
authenticated user
logout

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.0%

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 280896.

Affected configurations

Vulners
Vulnrichment
Node
ibmurbancode_deployRange7.07.0.5.20
OR
ibmurbancode_deployRange7.17.1.2.16
OR
ibmurbancode_deployRange7.27.2.3.9
OR
ibmurbancode_deployRange7.37.3.2.4
OR
ibmdevops_deployRange8.08.0.0.1
VendorProductVersionCPE
ibmurbancode_deploy*cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
ibmdevops_deploy*cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "UrbanCode Deploy",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "7.0.5.20",
        "status": "affected",
        "version": "7.0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "7.1.2.16",
        "status": "affected",
        "version": "7.1",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "7.2.3.9",
        "status": "affected",
        "version": "7.2",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "7.3.2.4",
        "status": "affected",
        "version": "7.3",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "DevOps Deploy",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "8.0.0.1",
        "status": "affected",
        "version": "8.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-22358