CVE-2016-0320

EUVD-2016-0355
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
ibmurbancode_deploy
6.0
ibmurbancode_deploy
6.0.1
ibmurbancode_deploy
6.0.1.1
ibmurbancode_deploy
6.0.1.2
ibmurbancode_deploy
6.0.1.3
ibmurbancode_deploy
6.0.1.4
ibmurbancode_deploy
6.0.1.5
ibmurbancode_deploy
6.0.1.6
ibmurbancode_deploy
6.0.1.7
ibmurbancode_deploy
6.0.1.8
ibmurbancode_deploy
6.0.1.9
ibmurbancode_deploy
6.0.1.10
ibmurbancode_deploy
6.0.1.11
ibmurbancode_deploy
6.0.1.12
ibmurbancode_deploy
6.0.1.13
ibmurbancode_deploy
6.0.1.14
ibmurbancode_deploy
6.1
ibmurbancode_deploy
6.1.0.1
ibmurbancode_deploy
6.1.0.2
ibmurbancode_deploy
6.1.0.3
ibmurbancode_deploy
6.1.0.4
ibmurbancode_deploy
6.1.1
ibmurbancode_deploy
6.1.1.1
ibmurbancode_deploy
6.1.1.2
ibmurbancode_deploy
6.1.1.3
ibmurbancode_deploy
6.1.1.4
ibmurbancode_deploy
6.1.1.5
ibmurbancode_deploy
6.1.1.6
ibmurbancode_deploy
6.1.1.7
ibmurbancode_deploy
6.1.1.8
ibmurbancode_deploy
6.1.2
ibmurbancode_deploy
6.1.3
ibmurbancode_deploy
6.1.3.1
ibmurbancode_deploy
6.1.3.2
ibmurbancode_deploy
6.1.3.3
ibmurbancode_deploy
6.2.0.0
ibmurbancode_deploy
6.2.0.1
ibmurbancode_deploy
6.2.0.2
ibmurbancode_deploy
6.2.1
ibmurbancode_deploy
6.2.1.1
ibmurbancode_deploy
6.2.2
ibmurbancode_deploy
6.2.2.1
𝑥
= Vulnerable software versions