Lucene search

K
ibmIBMA81894CAC87A48D85B184E8CFDFC8F3974523E5FA222D6926F96542370B60753
HistoryDec 13, 2023 - 10:00 p.m.

Security Bulletin: IBM UrbanCode Deploy (UCD) Agents as a windows service is vulnerable to a Denial Of Service (CVE-2023-42012)

2023-12-1322:00:21
www.ibm.com
9
ibm urbancode deploy
denial of service
windows service vulnerability
cve-2023-42012
affected versions
remediation
non-standard location

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Summary

An IBM UrbanCode Deploy (UCD) Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.

Vulnerability Details

CVEID:CVE-2023-42012
**DESCRIPTION:**An IBM UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/265509 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
UCD - IBM UrbanCode Deploy 7.2 - 7.2.3.7
UCD - IBM UrbanCode Deploy 7.3 - 7.3.2.2

Remediation/Fixes

IBM strongly suggests the following:

Upgrade affected versions to any of 7.2.3.8, 7.3.2.3, or 8.0.0.0 or later

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmurbancode_deployMatch8.0.0.0
CPENameOperatorVersion
ibm urbancode deployeq8.0.0.0

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for A81894CAC87A48D85B184E8CFDFC8F3974523E5FA222D6926F96542370B60753