6.2
CVE-2024-45091
- EPSS 0.01%
- Veröffentlicht 21.01.2025 01:15:07
- Zuletzt bearbeitet 29.01.2025 21:12:41
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM UrbanCode Deploy information disclosure
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Urbancode Deploy Version >= 7.0.0.0 < 7.0.5.25
Ibm ≫ Urbancode Deploy Version >= 7.1.0.0 < 7.1.2.21
Ibm ≫ Urbancode Deploy Version >= 7.2.0.0 < 7.2.3.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.