Vulnerability Bulletins |
IBM Security Bulletin: Exposed Authentication Token in IBM UrbanCode Deploy (CVE-2015-4964) |
|
| Affected software | IBM |
|
In previous versions of IBM UrbanCode Deploy, the authentication token is displayed in the execution logs. In certain steps that are run using the admin user permissions, this can allow non-administrator users to impersonate the admin user. In other processes, this can allow other users to impersonate the user who started the process. In either case, the token is invalidated when the step is completed. CVE(s): CVE-2015-4964 Affected product(s) and affected version(s): IBM UrbanCode More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_exposed_authentication_token_in_ibm_urbancode_deploy_cve_2015_4964?lang=en_us |
|






