IBM UrbanCode Deploy and IBM DevOps Deploy Agent Relay Service Missing Authentication Vulnerability

Vulnerability

A vulnerability exists in the Agent Relay service of IBM UrbanCode Deploy (UCD) versions 7.1 prior to 7.1.2.22, 7.2 prior to 7.2.3.15, and 7.3 prior to 7.3.2.10, as well as in IBM DevOps Deploy versions 8.0 prior to 8.0.1.5 and 8.1 prior to 8.1.0.1. This vulnerability could lead to unauthorized access to other services or the potential exposure of sensitive data, due to missing authentication in the Agent Relay service.

Impact

Exploitation of this vulnerability could result in unauthorized access to other services or the exposure of sensitive data.

Remediation

Users are advised to upgrade to version 7.1.2.23, 7.2.3.16, 7.3.2.11, 8.0.1.6 or 8.1.1.0. Instructions for downloading these versions are available on the IBM Support Fix Central website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.