IBM DevOps and UrbanCode Velocity Cryptographic Vulnerability Allowing Decryption of Sensitive Information

Vulnerability

A vulnerability exists in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.15, due to the use of weaker than expected cryptographic algorithms. This flaw could enable an attacker to decrypt highly sensitive information.

Impact

Exploitation of this vulnerability could lead to the unauthorized decryption of sensitive information, potentially exposing confidential data to attackers.

Remediation

Users are advised to upgrade to IBM DevOps Velocity version 5.0.1 or later, or to upgrade to IBM UrbanCode Velocity version 4.0.16 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.