Impact
IBM UCD is vulnerable to an information disclosure flaw that occurs when the system processes redacted properties containing certain non‑ASCII characters. The redaction engine may fail to mask ASCII secure values that are embedded inside unsecure properties, allowing an attacker to view sensitive data in plain text. The vulnerability does not allow code execution or denial of service, but it grants an authenticated user the ability to read confidential property values that should be hidden.
Affected Systems
IBM UCD – IBM UrbanCode Deploy and IBM DevOps Deploy are affected. For UrbanCode Deploy the vulnerable releases are 7.2 through 7.2.3.25 and 7.3 through 7.3.2.20. For DevOps Deploy the vulnerable releases are 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating moderate severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Attack requires authentication with permissions to view deployment request details and can be exploited via the web UI or the API. The vulnerability is not remote code execution, but it enables data leakage for users with the appropriate privileges.
OpenCVE Enrichment