CVE-2017-1749
CVE-2017-1749 is a medium-severity vulnerability in Ibm Urbancode Deploy with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Ibm Urbancode Deploy
- Published:
- Last modified:
Description
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
Frequently asked questions
- What is CVE-2017-1749?
- IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
- How severe is CVE-2017-1749?
- CVE-2017-1749 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2017-1749 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-1749?
- CVE-2017-1749 affects Ibm Urbancode Deploy. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2017-1749?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2017-1749 published?
- CVE-2017-1749 was published on 2018-08-13 and last updated on 2026-06-17.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/135522
- https://www.ibm.com/support/docview.wss?uid=swg2C1000374
Affected products (1)
- cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
More vulnerabilities in Ibm Urbancode Deploy
- CVE-2016-8938 — Critical (CVSS 10.0): IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code…
- CVE-2022-22315 — High (CVSS 8.8): IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated…
- CVE-2020-4202 — High (CVSS 8.8): IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the…
- CVE-2014-8900 — High (CVSS 8.8): Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and…
- CVE-2020-4481 — High (CVSS 8.2): IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection…
- CVE-2016-0271 — High (CVSS 8.2): The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a…
All CVEs affecting Ibm Urbancode Deploy →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.