IBM UrbanCode Velocity and DevOps Velocity CORS Vulnerability Allowing Privileged Actions and Information Retrieval

Vulnerability

A Cross-Origin Resource Sharing (CORS) vulnerability has been identified in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.15. The vulnerability arises because the CORS policy does not restrict domain names to trusted sources, potentially allowing attackers to perform privileged actions and access sensitive information.

Impact

Exploitation of this vulnerability could lead to unauthorized privileged actions and the retrieval of sensitive information.

Remediation

Users are advised to upgrade to IBM UrbanCode Velocity version 5.0.1 or later. Instructions for downloading the update are available on the IBM Support Fix Central website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.