CVE-2016-0364

EUVD-2016-0399
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
ibmurbancode_deploy
6.0
ibmurbancode_deploy
6.0.1.0
ibmurbancode_deploy
6.0.1.1
ibmurbancode_deploy
6.0.1.2
ibmurbancode_deploy
6.0.1.3
ibmurbancode_deploy
6.0.1.4
ibmurbancode_deploy
6.0.1.5
ibmurbancode_deploy
6.0.1.6
ibmurbancode_deploy
6.0.1.7
ibmurbancode_deploy
6.0.1.8
ibmurbancode_deploy
6.0.1.9
ibmurbancode_deploy
6.0.1.10
ibmurbancode_deploy
6.0.1.11
ibmurbancode_deploy
6.0.1.12
ibmurbancode_deploy
6.1
ibmurbancode_deploy
6.1.0.1
ibmurbancode_deploy
6.1.0.2
ibmurbancode_deploy
6.1.0.3
ibmurbancode_deploy
6.1.0.4
ibmurbancode_deploy
6.1.1.0
ibmurbancode_deploy
6.1.1.1
ibmurbancode_deploy
6.1.1.2
ibmurbancode_deploy
6.1.1.3
ibmurbancode_deploy
6.1.1.4
ibmurbancode_deploy
6.1.1.5
ibmurbancode_deploy
6.1.1.6
ibmurbancode_deploy
6.1.1.7
ibmurbancode_deploy
6.1.1.8
ibmurbancode_deploy
6.1.2
ibmurbancode_deploy
6.1.3
ibmurbancode_deploy
6.1.3.1
ibmurbancode_deploy
6.1.3.2
ibmurbancode_deploy
6.2.0.0
ibmurbancode_deploy
6.2.0.1
ibmurbancode_deploy
6.2.0.2
ibmurbancode_deploy
6.2.1
𝑥
= Vulnerable software versions