Severity
Medium
Analysis Summary
CVE-2025-13489 CVSS:5.9
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
CVE-2025-14148 CVSS:6.5
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2025-13489
CVE-2025-14148
Affected Vendors
- IBM
Affected Products
- IBM UCD - IBM DevOps Deploy 8.1
- IBM UCD - IBM DevOps Deploy 8.1.2.3
Remediation
IBM strongly suggests the following: Upgrade affected versions to any of 8.1.2.4 , 8.2.0.0 or later.

