IBM Security Bulletin: IBM UrbanCode Deploy diagnostics files may contain confidential data (CVE-2017-1286)

Previous releases of IBM UrbanCode Deploy diagnostics files can contain highly confidential data. This can include passwords and/or encrypted values.

CVE(s): CVE-2017-1286

Affected product(s) and affected version(s):

All fixpacks of IBM UrbanCode Deploy 6.1 – 6.1.3.6 and IBM UrbanCode Deploy 6.2 – 6.2.6.0 are affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=swg2C1000377
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/125147

The post IBM Security Bulletin: IBM UrbanCode Deploy diagnostics files may contain confidential data (CVE-2017-1286) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2vSPQr7