CVE-2024-45091

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Jan 21, 2025
CWE ID 532

Summary

CVE-2024-45091 is a vulnerability affecting IBM UrbanCode Deploy versions 7.0.5.24, 7.1.2.10, and 7.2.3.13. The issue lies in the logging functionality, where potentially sensitive information is stored in HTTP request logs. A local user with access to these logs can read the sensitive data, posing a security risk. IBM urges users to upgrade to the latest version or implement access controls to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM UrbanCode Deploy

Affected Vendors

  • IBM Corporation