VendorsIBMurbancode_deployall versions
Vulnerabilities

IBM UrbanCode Deploy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

66CVEs
CVE-2016-2994
Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-12-01 · Modified
5.4EPSS 0.006
CVE-2015-7415
Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Published 2016-01-01 · Modified
5.4EPSS 0.006
CVE-2016-9006
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.
Published 2017-03-08 · Modified
5.4EPSS 0.005
CVE-2025-1997
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy HTML injection
Published 2025-03-27 · Modified
5.4EPSS 0.003
CVE-2024-28781
IBM UrbanCode Deploy cross-site scripting
Published 2024-05-10 · Analyzed
5.4EPSS 0.003
CVE-2017-1749
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
Published 2018-08-13 · Modified
5.3EPSS 0.024
CVE-2023-42013
IBM UrbanCode Deploy information disclosure
Published 2023-12-19 · Modified
5.3EPSS 0.007
CVE-2025-36360
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Insufficient Session Expiration vulnerability
Published 2025-12-15 · Analyzed
5.0EPSS 0.002
CVE-2017-1752
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.
Published 2018-05-25 · Modified
4.9EPSS 0.016
CVE-2021-29711
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.
Published 2021-07-08 · Modified
4.9EPSS 0.006
CVE-2022-40751
IBM UrbanCode Deploy information disclosure
Published 2022-11-17 · Modified
4.9EPSS 0.006
CVE-2022-22366
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.
Published 2022-07-01 · Modified
4.9EPSS 0.004
CVE-2022-46771
IBM UrbanCode Deploy (UCD) cross-site scripting
Published 2022-12-20 · Modified
4.6EPSS 0.004
CVE-2024-22334
IBM UrbanCode Deploy improper privilege control
Published 2024-04-12 · Analyzed
4.4EPSS 0.004
CVE-2020-4483
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181857.
Published 2020-11-06 · Modified
4.3EPSS 0.010
CVE-2020-4260
IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic processes. IBM X-Force ID: 175639.
Published 2020-04-16 · Modified
4.3EPSS 0.009
CVE-2016-0364
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
Published 2016-07-01 · Modified
4.3EPSS 0.009
CVE-2020-4484
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force ID: 181858.
Published 2020-11-06 · Modified
4.3EPSS 0.008
CVE-2016-0373
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
Published 2018-08-30 · Modified
4.3EPSS 0.008
CVE-2016-0320
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
Published 2017-02-01 · Modified
4.3EPSS 0.006
CVE-2023-42015
IBM UrbanCode Deploy HTML injection
Published 2023-12-19 · Modified
4.3EPSS 0.006
CVE-2024-22339
IBM UrbanCode Deploy information disclosure
Published 2024-04-12 · Analyzed
4.3EPSS 0.004
CVE-2026-10569
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
Published 2026-07-30 · Analyzed
4.3EPSS 0.003
CVE-2014-6074
IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.
Published 2014-09-10 · Modified
4.0EPSS 0.011
CVE-2024-51472
IBM DevOps Deploy / IBM UrbanCode Deploy HTML injection
Published 2025-01-06 · Analyzed
3.1EPSS 0.003
CVE-2019-4666
IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1.5 could allow a local user to obtain sensitive information by unmasking certain secure values in documents. IBM X-Force ID: 171248.
Published 2020-02-13 · Modified
2.3EPSS 0.003
← Prev2 / 2