VendorsIBMurbancode_deployany version
Vulnerabilities

IBM UrbanCode Deploy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2020-4202
IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the server is configured to enable Distributed Front End (DFE). IBM X-Force ID: 174955.
Published 2020-04-23 · Modified
8.8EPSS 0.010
CVE-2022-22315
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.
Published 2022-04-27 · Modified
8.8EPSS 0.007
CVE-2014-8900
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
Published 2017-08-28 · Modified
8.8EPSS 0.006
CVE-2024-22358
IBM UrbanCode Deploy session fixation
Published 2024-04-12 · Analyzed
8.8EPSS 0.004
CVE-2022-22327
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.
Published 2022-04-01 · Modified
7.5EPSS 0.007
CVE-2024-55904
IBM DevOps Deploy / IBM UrbanCode Deploy command injection
Published 2025-02-14 · Analyzed
7.2EPSS 0.007
CVE-2017-1286
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
Published 2018-08-13 · Modified
6.5EPSS 0.013
CVE-2023-47161
IBM UrbanCode Deploy denial of service
Published 2023-12-19 · Modified
6.5EPSS 0.008
CVE-2022-35716
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.
Published 2022-07-31 · Modified
6.5EPSS 0.007
CVE-2023-40376
IBM UrbanCode Deploy (UCD) improper authentication controls
Published 2023-10-04 · Modified
6.5EPSS 0.005
CVE-2026-12085
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-54176
IBM UrbanCode Deploy missing authentication
Published 2025-02-08 · Analyzed
6.5EPSS 0.003
CVE-2024-56469
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authentication
Published 2025-03-27 · Analyzed
6.3EPSS 0.003
CVE-2019-4668
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.
Published 2020-04-23 · Modified
6.2EPSS 0.003
CVE-2023-42012
IBM UrbanCode Deploy denial of service
Published 2023-12-19 · Modified
6.2EPSS 0.002
CVE-2024-45091
IBM UrbanCode Deploy information disclosure
Published 2025-01-21 · Analyzed
6.2EPSS 0.002
CVE-2024-22331
IBM UrbanCode Deploy information disclosure
Published 2024-02-06 · Modified
6.2EPSS 0.002
CVE-2026-12086
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
Published 2026-06-30 · Modified
6.2EPSS 0.001
CVE-2024-22359
IBM UrbanCode Deploy cross-site scripting
Published 2024-04-12 · Analyzed
6.1EPSS 0.004
CVE-2022-43877
IBM UrbanCode Deploy (UCD) information disclosure
Published 2023-05-06 · Modified
5.5EPSS 0.002
CVE-2025-1998
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy information disclosure
Published 2025-03-27 · Analyzed
5.5EPSS 0.002
CVE-2025-1997
IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy HTML injection
Published 2025-03-27 · Modified
5.4EPSS 0.003
CVE-2024-28781
IBM UrbanCode Deploy cross-site scripting
Published 2024-05-10 · Analyzed
5.4EPSS 0.003
CVE-2017-1749
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
Published 2018-08-13 · Modified
5.3EPSS 0.024
CVE-2023-42013
IBM UrbanCode Deploy information disclosure
Published 2023-12-19 · Modified
5.3EPSS 0.007
CVE-2025-36360
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Insufficient Session Expiration vulnerability
Published 2025-12-15 · Analyzed
5.0EPSS 0.002
CVE-2017-1752
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.
Published 2018-05-25 · Modified
4.9EPSS 0.016
CVE-2021-29711
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.
Published 2021-07-08 · Modified
4.9EPSS 0.006
CVE-2022-40751
IBM UrbanCode Deploy information disclosure
Published 2022-11-17 · Modified
4.9EPSS 0.006
CVE-2022-46771
IBM UrbanCode Deploy (UCD) cross-site scripting
Published 2022-12-20 · Modified
4.6EPSS 0.004
CVE-2024-22334
IBM UrbanCode Deploy improper privilege control
Published 2024-04-12 · Analyzed
4.4EPSS 0.004
CVE-2020-4260
IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic processes. IBM X-Force ID: 175639.
Published 2020-04-16 · Modified
4.3EPSS 0.009
CVE-2016-0373
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
Published 2018-08-30 · Modified
4.3EPSS 0.008
CVE-2023-42015
IBM UrbanCode Deploy HTML injection
Published 2023-12-19 · Modified
4.3EPSS 0.006
CVE-2024-22339
IBM UrbanCode Deploy information disclosure
Published 2024-04-12 · Analyzed
4.3EPSS 0.004
CVE-2026-10569
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
Published 2026-07-30 · Analyzed
4.3EPSS 0.003
CVE-2024-51472
IBM DevOps Deploy / IBM UrbanCode Deploy HTML injection
Published 2025-01-06 · Analyzed
3.1EPSS 0.003
CVE-2019-4666
IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1.5 could allow a local user to obtain sensitive information by unmasking certain secure values in documents. IBM X-Force ID: 171248.
Published 2020-02-13 · Modified
2.3EPSS 0.003