Impact
IBM UrbanCode Deploy and IBM DevOps Deploy contain a flaw that allows an attacker with log file access to read confidential information captured in plugin output logs. This weakness results in a confidentiality breach, as secrets such as credentials or tokens may be leaked. The vulnerability is classified as CWE‑200 and does not provide any remote code execution or denial‑of‑service capability.
Affected Systems
Affected products include IBM UrbanCode Deploy versions 7.2 through 7.2.3.23 and 7.3 through 7.3.2.18, as well as IBM DevOps Deploy versions 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity; the EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The attack requires access to the logs, which can be local or remote depending on the deployment and logging configuration. Consequently, the risk is moderate but could become critical if an attacker can read logs from an external source or if sensitive data is routinely logged without sanitization.
OpenCVE Enrichment