Executive brief
IBM UrbanCode Deploy and DevOps Deploy, which are tools used to automate software deployments, contain a vulnerability where sensitive information is written to log files. An individual with local access to the system could read these logs to obtain confidential data. This could lead to unauthorized access to other systems or the exposure of credentials used during the deployment process.
Technical details
The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File). The IBM UrbanCode Deploy/DevOps Deploy installer and application components write sensitive data into log files with insufficient access controls or masking. A local attacker with access to the file system can read these logs to extract sensitive information without requiring elevated privileges. The issue affects multiple major versions (7.2, 7.3, 8.0, 8.1, and 8.2). IBM has released patches (7.2.3.24, 7.3.2.19, 8.0.1.14, 8.1.2.7, 8.2.2.0) to remediate the logging behavior.
Affected products
- IBM UrbanCode Deploy (UCD) / DevOps Deploy 7.2 through 7.2.3.23, 7.3 through 7.3.2.18, 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, 8.2 through 8.2.1.0
Timeline
- 2026-06-23: advisory: Initial publication by IBM
- 2026-06-30: disclosed: NVD publication date