VendorsIBMurbancode_deployall versions
Vulnerabilities

IBM UrbanCode Deploy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

66CVEs
CVE-2016-8938
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.
Published 2017-02-01 · Modified
10.0EPSS 0.028
CVE-2020-4202
IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the server is configured to enable Distributed Front End (DFE). IBM X-Force ID: 174955.
Published 2020-04-23 · Modified
8.8EPSS 0.010
CVE-2022-22315
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.
Published 2022-04-27 · Modified
8.8EPSS 0.007
CVE-2014-8900
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
Published 2017-08-28 · Modified
8.8EPSS 0.006
CVE-2024-22358
IBM UrbanCode Deploy session fixation
Published 2024-04-12 · Analyzed
8.8EPSS 0.004
CVE-2020-4481
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848.
Published 2020-08-05 · Modified
8.2EPSS 0.020
CVE-2016-0271
The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors.
Published 2016-07-08 · Modified
8.2EPSS 0.003
CVE-2017-1149
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.
Published 2017-04-25 · Modified
8.1EPSS 0.015
CVE-2016-0267
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
Published 2016-06-29 · Modified
7.7EPSS 0.010
CVE-2016-6068
IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.
Published 2017-02-01 · Modified
7.5EPSS 0.014
CVE-2016-9008
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
Published 2017-02-01 · Modified
7.5EPSS 0.010
CVE-2016-2942
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.
Published 2017-02-01 · Modified
7.5EPSS 0.008
CVE-2022-22327
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.
Published 2022-04-01 · Modified
7.5EPSS 0.007
CVE-2021-39082
IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published 2022-04-29 · Modified
7.5EPSS 0.007
CVE-2024-55904
IBM DevOps Deploy / IBM UrbanCode Deploy command injection
Published 2025-02-14 · Analyzed
7.2EPSS 0.007
CVE-2017-1286
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
Published 2018-08-13 · Modified
6.5EPSS 0.013
CVE-2020-4482
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls. IBM X-Force ID: 181856.
Published 2020-11-06 · Modified
6.5EPSS 0.009
CVE-2023-47161
IBM UrbanCode Deploy denial of service
Published 2023-12-19 · Modified
6.5EPSS 0.008
CVE-2022-35716
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.
Published 2022-07-31 · Modified
6.5EPSS 0.007
CVE-2023-40376
IBM UrbanCode Deploy (UCD) improper authentication controls
Published 2023-10-04 · Modified
6.5EPSS 0.005
CVE-2026-12085
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-54176
IBM UrbanCode Deploy missing authentication
Published 2025-02-08 · Analyzed
6.5EPSS 0.003
CVE-2024-56469
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authentication
Published 2025-03-27 · Analyzed
6.3EPSS 0.003
CVE-2019-4668
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.
Published 2020-04-23 · Modified
6.2EPSS 0.003
CVE-2023-42012
IBM UrbanCode Deploy denial of service
Published 2023-12-19 · Modified
6.2EPSS 0.002
CVE-2024-45091
IBM UrbanCode Deploy information disclosure
Published 2025-01-21 · Analyzed
6.2EPSS 0.002
CVE-2024-22331
IBM UrbanCode Deploy information disclosure
Published 2024-02-06 · Modified
6.2EPSS 0.002
CVE-2020-4884
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
Published 2021-03-30 · Modified
6.2EPSS 0.002
CVE-2026-12086
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
Published 2026-06-30 · Modified
6.2EPSS 0.001
CVE-2024-22359
IBM UrbanCode Deploy cross-site scripting
Published 2024-04-12 · Analyzed
6.1EPSS 0.004
CVE-2015-4964
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
Published 2015-10-05 · Modified
6.0EPSS 0.015
CVE-2016-0365
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.
Published 2016-07-01 · Modified
5.9EPSS 0.012
CVE-2019-4667
IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 171249.
Published 2020-05-11 · Modified
5.9EPSS 0.008
CVE-2017-1493
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.
Published 2018-01-09 · Modified
5.5EPSS 0.007
CVE-2020-4848
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that they should not have access to. IBM X-Force ID: 190293.
Published 2021-03-30 · Modified
5.5EPSS 0.006
CVE-2016-2941
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
Published 2017-02-01 · Modified
5.5EPSS 0.004
CVE-2022-43877
IBM UrbanCode Deploy (UCD) information disclosure
Published 2023-05-06 · Modified
5.5EPSS 0.002
CVE-2025-1998
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosure
Published 2025-03-27 · Analyzed
5.5EPSS 0.002
CVE-2020-4944
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
Published 2021-03-30 · Modified
5.5EPSS 0.002
CVE-2022-22367
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
Published 2022-07-01 · Modified
5.5EPSS 0.001
1 / 2Next →