IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.

Project Subscriptions

Vendors Products
Ucd Ibm Devops Deploy Subscribe
Ucd Ibm Urbancode Deploy Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly suggests the following: Upgrade affected versions to any of 7.2.3.26 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 7.3.2.21 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.0.1.16 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.1.2.9 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.2.2.2 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later


Workaround

No workaround given by the vendor.

History

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Title IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
First Time appeared Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
Weaknesses CWE-212
CPEs cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.1.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.3.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.2.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ucd Ibm Devops Deploy
Ibm ucd Ibm Urbancode Deploy
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T15:10:10.775Z

Reserved: 2026-08-24T23:34:03.185Z

Link: CVE-2026-78658

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses