Vulnerability Description
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Urbancode Deploy | >= 6.0, <= 6.2.2.1 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/112119VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/112119VDB EntryVendor Advisory
FAQ
What is CVE-2016-0373?
CVE-2016-0373 is a vulnerability with a CVSS score of 3.1 (LOW). IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IB...
How severe is CVE-2016-0373?
CVE-2016-0373 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0373?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Urbancode Deploy.