CVE-2023-40376
04.10.2023, 14:15
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | urbancode_deploy | 7.1 ≤ 𝑥 ≤ 7.1.2.12 |
ibm | urbancode_deploy | 7.2 ≤ 𝑥 ≤ 7.2.3.5 |
ibm | urbancode_deploy | 7.3 ≤ 𝑥 ≤ 7.3.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.