CVE-2025-31991
- EPSS 0.23%
- Veröffentlicht 13.04.2026 15:56:41
- Zuletzt bearbeitet 07.10.2026 09:10:00
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
CVE-2024-22347
- EPSS 0.32%
- Veröffentlicht 20.01.2025 18:15:13
- Zuletzt bearbeitet 27.07.2026 18:14:16
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2024-22348
- EPSS 0.36%
- Veröffentlicht 20.01.2025 18:15:13
- Zuletzt bearbeitet 27.07.2026 18:14:16
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limi...
CVE-2024-22349
- EPSS 0.21%
- Veröffentlicht 20.01.2025 18:15:13
- Zuletzt bearbeitet 27.07.2026 18:14:16
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.