Rewterz
Rewterz Threat Advisory – Multiple IBM Financial Transaction Manager Vulnerabilities
December 26, 2022
Rewterz
Rewterz Threat Advisory – Multiple IBM Cognos Analytics Vulnerabilities
December 26, 2022

Rewterz Threat Advisory – CVE-2022-46771 – IBM UrbanCode Deploy (UCD) Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-46771

IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Impact

  • Cross-Site Scripting

Indicators Of Compromise

CVE

  • CVE-2022-46771

Affected Vendors

IBM

Affected Products

  • IBM UrbanCode Deploy 7.1.0.0
  • IBM UrbanCode Deploy 6.2.7.18
  • IBM UrbanCode Deploy 7.0.5.13
  • IBM UrbanCode Deploy 7.1.2.9
  • IBM UrbanCode Deploy 7.2.3.2
  • IBM UrbanCode Deploy 7.3.0.0
  • IBM UrbanCode Deploy 7.0.5.0
  • IBM UrbanCode Deploy 7.2.0.0
  • IBM UrbanCode Deploy 6.2.0.0

Remediation

Refer to IBM Security Advisory for patch, upgrade or suggested workaround information. 

IBM Security Advisory