CVE-2017-1286
https://notcve.org/view.php?id=CVE-2017-1286
13 Aug 2018 — Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147. La información sensible sobre la configuración del servidor y la base de datos de IBM UrbanCode Deploy desde la versión 6.1 hasta la 6.9.6.0 puede ser obtenida por un usuario al que se le hayan otorgado permisos elevados en la interfaz de u... • https://exchange.xforce.ibmcloud.com/vulnerabilities/125147 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1752
https://notcve.org/view.php?id=CVE-2017-1752
25 May 2018 — IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547. IBM UrbanCode Deploy 6.1 y 6.2 podría permitir que un usuario autenticado privilegiado obtenga información altamente sensible. IBM X-Force ID: 135547. • http://www.ibm.com/support/docview.wss?uid=swg2C1000376 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1493
https://notcve.org/view.php?id=CVE-2017-1493
09 Jan 2018 — IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691. IBM UrbanCode Deploy (UCD) 6.1 y 6.2 podría permitir que un usuario autenticado edite objetos a los que no debería tener acceso, debido a controles de acceso incorrectos. IBM X-Force ID: 128691. • http://www.ibm.com/support/docview.wss?uid=swg2C1000367 • CWE-269: Improper Privilege Management •
CVE-2014-8900
https://notcve.org/view.php?id=CVE-2014-8900
28 Aug 2017 — Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier. Existe una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en IBM UrbanCode Release 6.0.1.6 y anteriores, 6.1.0.7 y anteriores y 6.1.1.1 y anteriores. • http://www-01.ibm.com/support/docview.wss?uid=swg21695293 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2017-1149
https://notcve.org/view.php?id=CVE-2017-1149
25 Apr 2017 — IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202. IBM UrbanCode Deploy (UCD) 6.0, 6.1, y 6.2 es vulnerable a una denegación de servicio, provocada por un error XML External Entity Injection (XXE) cuando procesa datos XML. Un atacante remoto ... • http://www.ibm.com/support/docview.wss?uid=swg2C1000289 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2016-9006
https://notcve.org/view.php?id=CVE-2016-9006
08 Mar 2017 — IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264. IBM UrbanCode Deploy 6.1 y 6.2 es vulnerable a XSS. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la interfaz web alterando así la funcionalidad prevista potencialmente conduciendo a l... • http://www.ibm.com/support/docview.wss?uid=swg2C1000264 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-0320
https://notcve.org/view.php?id=CVE-2016-0320
01 Feb 2017 — IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes. IBM UrbanCode Deploy podría permitir a un usuario autenticado modificar objetos Ucd debido a que múltiples endpoints REST no autorizan adecuadamente a los usuarios la edición de objetos UCD. Esto podría afectar el comportamiento de los procesos legítimamente desencadenados. • http://www.ibm.com/support/docview.wss?uid=swg2C1000222 • CWE-284: Improper Access Control •
CVE-2016-2942
https://notcve.org/view.php?id=CVE-2016-2942
01 Feb 2017 — IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine. IBM UrbanCode Deploy podría permitir a un atacante autenticado con permisos especiales crear una secuencia de comandos en el servidor de manera que los procesos se ejecuten en una máquina de agente UCD remota. • http://www.ibm.com/support/docview.wss?uid=swg2C1000218 • CWE-284: Improper Access Control •
CVE-2016-9008
https://notcve.org/view.php?id=CVE-2016-9008
01 Feb 2017 — IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent. IBM UrbanCode Deploy podría permitir a un usuario malintencionado acceder a la interfaz Agente Relay ActiveMQ Broker JMX y ejecutar complementos en el agente. • http://www.ibm.com/support/docview.wss?uid=swg2C1000238 • CWE-284: Improper Access Control •
CVE-2016-2941
https://notcve.org/view.php?id=CVE-2016-2941
01 Feb 2017 — IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user. IBM UrbanCode Deploy crea archivos temporales durante la ejecución de pasos que podrían contener información sensible incluyendo contraseñas que podrían ser leídas por un usuario local. • http://www.ibm.com/support/docview.wss?uid=swg2C1000220 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •