CVE-2024-22349 MEDIUM

CVE-2024-22349: IBM UrbanCode Velocity information disclosure

Vendor Ibm
Product UrbanCode Velocity
Weakness CWE-525
Published January 20, 2025
Last update January 21, 2025

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.

Key dates

02Disclosure timeline

January 20, 2025 CVE published
January 21, 2025 Record updated