IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/128691 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/102483 | vdb entry third party advisory |
http://www.ibm.com/support/docview.wss?uid=swg2C1000367 | vendor advisory |