CVE-2023-42015: IBM Urbancode Deploy

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512.

Affected products

  • IBM Urbancode Deploy: from 7.1.0.0, before 7.1.2.15 (fixed in 7.1.2.15); from 7.2.0.0, before 7.2.3.8 (fixed in 7.2.3.8); from 7.3.0.0, before 7.3.2.3 (fixed in 7.3.2.3)

Published 2023-12-19. Last modified 2026-06-17.