IBM DevOps and UrbanCode Velocity Local Storage Vulnerability Allowing Cross-User Access
Vulnerability
A vulnerability exists in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.25, allowing web pages to be stored locally and accessed by other users on the same system. This issue arises from improper handling of local storage, which can lead to unauthorized access to stored data.
Impact
Exploitation of this vulnerability could result in unauthorized access to locally stored web page data by another user on the system.
Remediation
Users are advised to upgrade to IBM DevOps Velocity version 5.0.1 or later. For IBM UrbanCode Velocity, version 5.0.1 is also recommended. Instructions for downloading the update are available on the IBM Support Fix Central website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
