Description
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM UCD is vulnerable to an information disclosure flaw that occurs when the system processes redacted properties containing certain non‑ASCII characters. The redaction engine may fail to mask ASCII secure values that are embedded inside unsecure properties, allowing an attacker to view sensitive data in plain text. The vulnerability does not allow code execution or denial of service, but it grants an authenticated user the ability to read confidential property values that should be hidden.

Affected Systems

IBM UCD – IBM UrbanCode Deploy and IBM DevOps Deploy are affected. For UrbanCode Deploy the vulnerable releases are 7.2 through 7.2.3.25 and 7.3 through 7.3.2.20. For DevOps Deploy the vulnerable releases are 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1.

Risk and Exploitability

The flaw has a CVSS score of 6.5, indicating moderate severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Attack requires authentication with permissions to view deployment request details and can be exploited via the web UI or the API. The vulnerability is not remote code execution, but it enables data leakage for users with the appropriate privileges.

Generated by OpenCVE AI on September 4, 2026 at 16:45 UTC.

Remediation

Vendor Solution

IBM strongly suggests the following: Upgrade affected versions to any of 7.2.3.26 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 7.3.2.21 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.0.1.16 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.1.2.9 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.2.2.2 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later


OpenCVE Recommended Actions

  • Upgrade IBM UCD to any of the supported fixed releases—7.2.3.26, 7.3.2.21, 8.0.1.16, 8.1.2.9, 8.2.2.2 or later depending on your product line.
  • After the upgrade, test the redaction functionality by creating a deployment that includes a secure property with non‑ASCII characters and confirm that the value is correctly masked in the UI and API responses.
  • If an upgrade cannot be performed immediately, limit or revoke users’ permissions to view deployment requests and isolate the affected UCD instance from untrusted networks until the patch is applied.

Generated by OpenCVE AI on September 4, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Title IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
First Time appeared Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
Weaknesses CWE-212
CPEs cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.1.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.3.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.2.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Ucd Ibm Devops Deploy Ucd Ibm Urbancode Deploy
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:35.464Z

Reserved: 2026-08-24T23:34:03.185Z

Link: CVE-2026-78658

cve-icon Vulnrichment

Updated: 2026-09-10T20:57:12.536Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T16:17:59.823

Modified: 2026-09-10T21:17:46.440

Link: CVE-2026-78658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:45:17Z

Weaknesses
  • CWE-212

    Improper Removal of Sensitive Information Before Storage or Transfer