Executive brief
IBM UrbanCode Deploy and DevOps Deploy, tools used to automate software deployments across an organization, are affected by a vulnerability that leaks sensitive information into plugin output logs. An authorized user with access to these logs could view sensitive values, such as credentials or configuration secrets, that were intended to be protected. This could lead to unauthorized access to other systems or data handled during the deployment process.
Technical details
IBM UrbanCode Deploy and DevOps Deploy are vulnerable to CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) within their plugin output logs. The vulnerability allows an authenticated attacker with network access and log-viewing permissions to obtain sensitive values related to specific deployment steps. The root cause is the failure of the application to properly mask or redact sensitive data before writing it to the plugin execution logs. IBM has released patches to address this issue, and users are advised to upgrade to versions 7.2.3.24, 7.3.2.19, 8.0.1.14, 8.1.2.7, or 8.2.2.0.
Affected products
- IBM UrbanCode Deploy (UCD) 7.2 - 7.2.3.23, 7.3 - 7.3.2.18
- IBM DevOps Deploy 8.0 - 8.0.1.13, 8.1 - 8.1.2.6, 8.2 - 8.2.1.0
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-23: patched: Fixes released in versions 7.2.3.24, 7.3.2.19, 8.0.1.14, 8.1.2.7, and 8.2.2.0
- 2026-07-30: advisory: NVD publication date