CVE-2024-22334 MEDIUM

CVE-2024-22334: IBM UrbanCode Deploy improper privilege control

Vendor Ibm
Product UrbanCode Deploy
Weakness CWE-732
Published April 12, 2024
Last update August 1, 2024

CVSS base score

4.4/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated permissions of objects using that type may not be fully revoked. This could lead to incorrect reporting of permission configuration and unexpected privileges being retained. IBM X-Force ID: 279974.

Key dates

02Disclosure timeline

April 12, 2024 CVE published
August 1, 2024 Record updated