IBM DevOps Deploy
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*
- >= 8.1, <= 8.1.2.3
A vulnerability exists in IBM UrbanCode Deploy (UCD) versions 8.1 through 8.1.2.3, allowing an authenticated user with privileges to configure LLM integration to retrieve a previously saved LLM API token. This issue is categorized as insufficiently protected credentials.
Exploitation of this vulnerability could lead to unauthorized access to LLM API tokens, potentially allowing for misuse of the LLM integration capabilities within the application.
Users are advised to upgrade to version 8.1.2.4 or 8.2.0.0. Instructions for downloading these versions are available on the IBM Support Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.