CVE-2025-1998

IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensitive authentication token information in log files that could be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7229034 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:8.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*

History

14 Aug 2025, 19:13

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7229034 - () https://www.ibm.com/support/pages/node/7229034 - Vendor Advisory
CPE cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:8.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
Summary
  • (es) IBM UrbanCode Deploy (UCD) versiones 7.1.2.21, 7.2 a 7.2.3.14 y 7.3 a 7.3.2.0 / IBM DevOps Deploy versiones 8.0 a 8.0.1.4 y 8.1 a 8.1 almacenan información de token de autenticación potencialmente confidencial en archivos de registro que un usuario local podría leer.
First Time Ibm
Ibm devops Deploy
Ibm urbancode Deploy

27 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-27 15:15

Updated : 2025-08-14 19:13


NVD link : CVE-2025-1998

Mitre link : CVE-2025-1998

CVE.ORG link : CVE-2025-1998


JSON object : View

Products Affected

ibm

  • devops_deploy
  • urbancode_deploy
CWE
CWE-532

Insertion of Sensitive Information into Log File