CVE-2024-22331: IBM Devops Deploy

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971.

Affected products

  • IBM Devops Deploy: version 8.0.0.0 only
  • IBM Urbancode Deploy: from 7.0.0.0, before 7.0.5.20 (fixed in 7.0.5.20); from 7.1.0.0, before 7.1.2.16 (fixed in 7.1.2.16); from 7.2.0.0, before 7.2.3.9 (fixed in 7.2.3.9); from 7.3.0.0, before 7.3.2.4 (fixed in 7.3.2.4)

Published 2024-02-06. Last modified 2026-06-17.