IBM UrbanCode Deploy and IBM DevOps Deploy HTML Injection Vulnerability

Vulnerability

A vulnerability allowing HTML injection has been identified in IBM UrbanCode Deploy (UCD) versions 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3. This vulnerability could enable a user to inject arbitrary HTML tags into the Web UI, potentially leading to the disclosure of sensitive information.

Impact

Exploitation of this vulnerability could result in HTML injection, allowing for the embedding of arbitrary HTML in the Web UI, which could be used to disclose sensitive information.

Remediation

Users are advised to upgrade to version 7.2.3.14, 7.3.2.9, 8.0.1.4, 8.1.0.0 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.