IBM DevOps and UrbanCode Velocity Local Storage Vulnerability Allowing Cross-User Access

Vulnerability

A vulnerability exists in IBM DevOps Velocity version 5.0.0 and IBM UrbanCode Velocity versions 4.0.0 through 4.0.25, allowing web pages to be stored locally and accessed by other users on the same system. This issue arises from improper handling of local storage, which can lead to unauthorized access to stored data.

Impact

Exploitation of this vulnerability could result in unauthorized access to locally stored web page data by another user on the system.

Remediation

Users are advised to upgrade to IBM DevOps Velocity version 5.0.1 or later. For IBM UrbanCode Velocity, version 5.0.1 is also recommended. Instructions for downloading the update are available on the IBM Support Fix Central website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.