Description
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated, potentially enabling unauthorized access under certain network conditions.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
- ibm / ucd_ibm_devops_deploy8.0 – 8.0
- ibm / ucd_ibm_devops_deploy8.0.1.10 – 8.0.1.10
- ibm / ucd_ibm_devops_deploy8.1 – 8.1
- ibm / ucd_ibm_devops_deploy8.1.2.3 – 8.1.2.3
- ibm / ucd_ibm_urbancode_deploy7.3 – 7.3
- ibm / ucd_ibm_urbancode_deploy7.1 – 7.1
- ibm / ucd_ibm_urbancode_deploy7.3.2.15 – 7.3.2.15
- ibm / ucd_ibm_urbancode_deploy7.1.2.27 – 7.1.2.27
- ibm / ucd_ibm_urbancode_deploy7.2 – 7.2
- ibm / ucd_ibm_urbancode_deploy7.2.3.20 – 7.2.3.20
References
Updated 14m ago · 8 sources