CVE-2026-10569

Summary

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

Affected Software

VendorProductVersion RangeStatus
IBMUCD - IBM UrbanCode Deploy7.2 <= 7.2.3.23affected
IBMUCD - IBM UrbanCode Deploy7.3 <= 7.3.2.18affected
IBMUCD - IBM DevOps Deploy8.0 <= 8.0.1.13affected
IBMUCD - IBM DevOps Deploy8.1 <= 8.1.2.6affected
IBMUCD - IBM DevOps Deploy8.2 <= 8.2.1.0affected

Weaknesses

  • CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References