📦 Urbancode Deploy

by Ibm

🔍 What is Urbancode Deploy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-55904

HIGH CVSS 7.2 Feb 14, 2025

This vulnerability allows authenticated privileged attackers to execute arbitrary commands on IBM DevOps Deploy and UrbanCode Deploy systems by sending specially crafted input. It affects multiple ver...

CVE-2021-39082

HIGH CVSS 7.5 Apr 29, 2022

IBM UrbanCode Deploy 7.1.1.2 uses weak cryptographic algorithms that could allow attackers to decrypt sensitive information stored or transmitted by the system. This affects organizations using the vu...

CVE-2022-22315

HIGH CVSS 8.8 Apr 27, 2022

CVE-2022-22315 is a privilege escalation vulnerability in IBM UrbanCode Deploy that allows authenticated users with special permissions to gain elevated privileges due to improper permission handling....

CVE-2022-22327

HIGH CVSS 7.5 Apr 1, 2022

This vulnerability in IBM UrbanCode Deploy uses weak cryptographic algorithms that could allow attackers to decrypt sensitive information stored or transmitted by the application. It affects IBM Urban...

CVE-2025-36360

MEDIUM CVSS 5.0 Dec 15, 2025

This CVE describes a race condition vulnerability in IBM UrbanCode Deploy and DevOps Deploy where HTTP session client-IP binding enforcement can be bypassed. An attacker could briefly reuse a session ...

CVE-2024-54176

MEDIUM CVSS 4.3 Feb 8, 2025

This vulnerability in IBM DevOps Deploy and UrbanCode Deploy allows authenticated users to access sensitive information about other users due to missing authorization checks. It affects multiple versi...

CVE-2024-45091

MEDIUM CVSS 6.2 Jan 21, 2025

IBM UrbanCode Deploy versions 7.0 through 7.2.3.13 store sensitive information in HTTP request logs that could be read by local users. This information disclosure vulnerability allows attackers with l...

CVE-2024-28781

MEDIUM CVSS 5.4 May 14, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy that allows authenticated users to inject malicious JavaScript into the web interface. Successful exploitation cou...