CVE-2024-55904

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
References
Link Resource
https://www.ibm.com/support/pages/node/7182841 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:8.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*

History

18 Aug 2025, 18:14

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7182841 - () https://www.ibm.com/support/pages/node/7182841 - Vendor Advisory
CPE cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:8.1.0.0:*:*:*:*:*:*:*
Summary
  • (es) IBM DevOps Deploy 8.0 a 8.0.1.4, 8.1 a 8.1.0.0 / IBM UrbanCode Deploy 7.0 a 7.0.5.25, 7.1 a 7.1.2.21, 7.2 a 7.2.3.14 y 7.3 a 7.3.2.9 podrían permitir que un atacante remoto autenticado y privilegiado ejecute comandos arbitrarios en el sistema mediante el envío de entradas especialmente manipuladas que contengan elementos especiales.
First Time Ibm
Ibm urbancode Deploy
Ibm devops Deploy

14 Feb 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 04:15

Updated : 2025-08-18 18:14


NVD link : CVE-2024-55904

Mitre link : CVE-2024-55904

CVE.ORG link : CVE-2024-55904


JSON object : View

Products Affected

ibm

  • urbancode_deploy
  • devops_deploy
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')