CVE-2023-40376: IBM Urbancode Deploy
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.
Affected products
- IBM Urbancode Deploy: from 7.1, up to and including 7.1.2.12; from 7.2, up to and including 7.2.3.5; from 7.3, up to and including 7.3.2.0
Published 2023-10-04. Last modified 2026-06-17.