CVE-2025-1998
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-1998 is a vulnerability affecting IBM UrbanCode Deploy versions 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0, as well as IBM DevOps Deploy versions 8.0 through 8.0.1.4 and 8.1. This issue allows local users to gain unauthorized access to potentially sensitive authentication token information, which is stored in log files. The impact of this vulnerability is significant, as it could enable an attacker to gain unauthorized access to IBM UrbanCode Deploy or IBM DevOps Deploy systems, leading to potential data breaches or system compromise. IBM recommends users to upgrade to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM UrbanCode Deploy
Affected Vendors
- IBM Corporation