漏洞描述 IBM UrbanCode Deploy(UCD)是美国国际商业机器(IBM)公司的一套应用自动化部署工具。该工具基于一个应用部署自动化管理信息模型,并通过远程代理技术,实现对复杂应用在不同环境下的自动化部署等。 IBM UrbanCode Deploy 存在日志信息泄露漏洞,该漏洞源于敏感值混淆不够,容易遭受敏感信息泄露漏洞。
相关漏洞推荐 POC CVE-2023-28432: MinIO Cluster Deployment - Information Disclosure POC vpc-endpoints-not-deployed: VPC Endpoints Not Deployed POC azure-appservice-ftp-deployment-disabled: Azure App Service Plain FTP Deployment Disabled POC k8s-cpu-limits-not-set: CPU limits not set in Deployments POC k8s-cpu-requests-not-set: CPU Requests not set in Deployments POC k8s-default-namespace-used: Default Namespace Usage in Deployments POC k8s-liveness-probe-not-configured: Liveness Probe Not Configured in Deployments POC k8s-memory-limits-not-set: Memory limits not set in Deployments POC k8s-memory-requests-not-set: Memory requests not set in Deployments POC k8s-privileged-containers: Privileged Containers Found in Deployments POC k8s-readiness-probe-not-set: Readiness Probes not set in Deployments POC deployment-ini: FTP Deployment Config File - Exposure POC deployment-interface-exposed: Deployment Management Interface - Exposed