CVE-2024-22348
20.01.2025, 18:15
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ibm | devops_velocity | 5.0.0 |
| ibm | urbancode_velocity | 4.0.0 ≤ 𝑥 ≤ 4.0.15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration