3.3
CVE-2024-22349
- EPSS 0.21%
- Veröffentlicht 20.01.2025 18:15:13
- Zuletzt bearbeitet 27.07.2026 18:14:16
- Erkennungen
IBM UrbanCode Velocity information disclosure
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Devops Velocity Version 5.0.0
Ibm ≫ Urbancode Velocity Version >= 4.0.0 <= 4.0.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.115 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| IBM | 4 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-525 Use of Web Browser Cache Containing Sensitive Information
The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
https://www.ibm.com/support/pages/node/7172750