CVE-2024-51472

IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
References
Link Resource
https://www.ibm.com/support/pages/node/7177856 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*

History

20 Jun 2025, 18:09

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7177856 - () https://www.ibm.com/support/pages/node/7177856 - Vendor Advisory
First Time Ibm devops Deploy
Ibm
Ibm urbancode Deploy
Summary
  • (es) IBM UrbanCode Deploy (UCD) 7.2 a 7.2.3.13, 7.3 a 7.3.2.8 e IBM DevOps Deploy 8.0 a 8.0.1.3 son vulnerables a la inyección de HTML. Esta vulnerabilidad puede permitir que un usuario incorpore etiquetas HTML arbitrarias en la interfaz de usuario web, lo que podría provocar la divulgación de información confidencial.

06 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 17:15

Updated : 2025-06-20 18:09


NVD link : CVE-2024-51472

Mitre link : CVE-2024-51472

CVE.ORG link : CVE-2024-51472


JSON object : View

Products Affected

ibm

  • urbancode_deploy
  • devops_deploy
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')