Lucene search

K
ibmIBM7A6BB496FE26603B63F0FFBE8159DD77814309FC3C3D3A21AB2E75CCAF01DD1B
HistoryApr 03, 2019 - 7:55 p.m.

Security Bulletin: An Authenticated Agent Can Modify Another Agent's Properties (CVE-2018-1995)

2019-04-0319:55:01
www.ibm.com
11

0.003 Low

EPSS

Percentile

68.7%

Summary

Old versions of UrbanCode Deploy web agents can allow unauthorized property modification of other agents.

Vulnerability Details

CVEID: CVE-2018-1995 Details:
An authenticated agent can modify another agent’s properties using a specially crafted request.

Consequences:
Agent properties can be modified.

Remedy:
Upgrade all Web Agents to 7.0.1.2 or later, or use JMS communication instead.

Affected Products and Versions

All Web communication agents of IBM UrbanCode Deploy with versions 6.2.7.3 -6.2.7.4, and 7.0-7.0.1.1 are affected.
Agents using JMS communication are not affected.

Remediation/Fixes

Upgrade agents to IBM UrbanCode Deploy 7.0.1.2 or later.
Alternatively, switch agents to JMS communication while waiting to upgrade.

Workarounds and Mitigations

Switch agents from Web communication to JMS until upgrading is possible.