Lucene search

K
ibmIBMAE33DAC109C9ED07F39EA6B95660C25C0631C4BBAD4A0169964259E907DCAC77
HistoryJul 29, 2022 - 7:24 p.m.

Security Bulletin: Urbancode Deploy is vulnerable to incorrect authorization reading Component Processes ( CVE-2022-35716 )

2022-07-2919:24:41
www.ibm.com
27
ibm
urbancode deploy
cve-2022-35716
security checking
authentication
sensitive information
cvss
version
upgrade
fix
endpoint
validation

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

34.8%

Summary

Component process security checks can sometimes grant read-level access to users that do not have access if the process is owned by a Component Template and an endpoint performs multiple validations.

Vulnerability Details

CVEID:CVE-2022-35716
**DESCRIPTION:**IBM UrbanCode Deploy (UCD) could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/231360 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
UCD - IBM UrbanCode Deploy 6.2.0.0 - 6.2.7.16
UCD - IBM UrbanCode Deploy 7.0.0.0 - 7.0.5.11
UCD - IBM UrbanCode Deploy 7.1.0.0 - 7.1.2.7
UCD - IBM UrbanCode Deploy 7.2.0.0 - 7.2.3.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading to any of 6.2.7.17, 7.0.5.12, 7.1.2.8, 7.2.3.1 or later.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmurbancode_deployMatch7.2.3.1
VendorProductVersionCPE
ibmurbancode_deploy7.2.3.1cpe:2.3:a:ibm:urbancode_deploy:7.2.3.1:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

34.8%

Related for AE33DAC109C9ED07F39EA6B95660C25C0631C4BBAD4A0169964259E907DCAC77