Description
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM UrbanCode Deploy and IBM DevOps Deploy contain a flaw that allows an attacker with log file access to read confidential information captured in plugin output logs. This weakness results in a confidentiality breach, as secrets such as credentials or tokens may be leaked. The vulnerability is classified as CWE‑200 and does not provide any remote code execution or denial‑of‑service capability.

Affected Systems

Affected products include IBM UrbanCode Deploy versions 7.2 through 7.2.3.23 and 7.3 through 7.3.2.18, as well as IBM DevOps Deploy versions 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity; the EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The attack requires access to the logs, which can be local or remote depending on the deployment and logging configuration. Consequently, the risk is moderate but could become critical if an attacker can read logs from an external source or if sensitive data is routinely logged without sanitization.

Generated by OpenCVE AI on August 3, 2026 at 10:32 UTC.

Remediation

Vendor Solution

IBM strongly suggests the following: Upgrade affected versions to any of 7.2.3.24 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 7.3.2.19 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.0.1.14 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.1.2.7 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.2.2.0 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later


OpenCVE Recommended Actions

  • Upgrade IBM DevOps Deploy to version 8.0.1.14 or newer, 8.1.2.7 or newer, or 8.2.2.0 or newer; upgrade IBM UrbanCode Deploy to 7.2.3.24 or newer, 7.3.2.19 or newer, or newer releases as available. For each upgrade, download the corresponding fix from IBM Fix Central: https://www.ibm.com/support/fixcentral/swg/downloadFixes.
  • Review log configuration to mask or remove sensitive values before writing them to output logs.
  • Limit log file access to authorized personnel only and enforce strict permissions on log directories.

Generated by OpenCVE AI on August 3, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
Vendors & Products Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
Title IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
First Time appeared Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.1.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.3.23:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.2.18:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Devops Deploy Ucd Ibm Devops Deploy Ucd Ibm Urbancode Deploy Ucd Ibm Devops Deploy Ucd Ibm Urbancode Deploy Urbancode Deploy
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T19:33:20.270Z

Reserved: 2026-06-01T16:46:32.738Z

Link: CVE-2026-10569

cve-icon Vulnrichment

Updated: 2026-07-30T19:31:55.087Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T20:16:51.940

Modified: 2026-08-10T19:56:22.510

Link: CVE-2026-10569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor