IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7172750 |
![]() ![]() |
History
Tue, 21 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 20 Jan 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. | |
Title | IBM UrbanCode Velocity cross-origin resource sharing | |
First Time appeared |
Ibm
Ibm devops Velocity Ibm urbancode Velocity |
|
Weaknesses | CWE-942 | |
CPEs | cpe:2.3:a:ibm:devops_velocity:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:urbancode_velocity:4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:urbancode_velocity:4.0.15:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm devops Velocity Ibm urbancode Velocity |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-21T14:47:02.451Z
Reserved: 2024-01-08T23:42:25.451Z
Link: CVE-2024-22348

Updated: 2025-01-21T14:46:53.929Z

Status : Received
Published: 2025-01-20T18:15:13.737
Modified: 2025-01-20T18:15:13.737
Link: CVE-2024-22348

No data.