Back to overview

CVE-2026-12084

MEDIUM
5.4
CVSS 3.1
Description
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

Metadata

CVE ID
CVE-2026-12084
State
PUBLISHED
Assigner
ibm
Reserved
2026-06-12 13:08 UTC
Published
2026-06-30 19:39 UTC
Last updated
2026-06-30 19:39 UTC
Primary CWE
CWE-942
CWE-942 Permissive Cross-domain Security Policy with Untrust…
Vendor / Product
IBM / UCD - IBM DevOps Deploy
Sources
cve.org  ·  NVD

Severity & Metrics

5.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products (1)
VendorProductPlatformVersions
IBM UCD - IBM DevOps Deploy 8.1.0 ≤ 8.1.2.6, 8.2.0 ≤ 8.2.1.0
Weakness (CWE)
CWESourceDescription
CWE-942 cna CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Back to overview