IBM UrbanCode Deploy 6.0 and 6.0.1.x prior to 6.0.1.10, 6.1.1.x prior to 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm urbancode deploy 6.0.1.0 |
||
ibm urbancode deploy 6.0.1.2 |
||
ibm urbancode deploy 6.0.1.9 |
||
ibm urbancode deploy 6.1.1.1 |
||
ibm urbancode deploy 6.1.2 |
||
ibm urbancode deploy 6.0 |
||
ibm urbancode deploy 6.1.1.3 |
||
ibm urbancode deploy 6.1.1.4 |
||
ibm urbancode deploy 6.1.1.5 |
||
ibm urbancode deploy 6.1.1.6 |
||
ibm urbancode deploy 6.0.1.4 |
||
ibm urbancode deploy 6.0.1.5 |
||
ibm urbancode deploy 6.0.1.6 |
||
ibm urbancode deploy 6.0.1.7 |
||
ibm urbancode deploy 6.0.1.8 |
||
ibm urbancode deploy 6.0.1.1 |
||
ibm urbancode deploy 6.0.1.3 |
||
ibm urbancode deploy 6.1.1.0 |
||
ibm urbancode deploy 6.1.1.2 |
||
ibm urbancode deploy 6.1.1.7 |