CVE-2022-40751 is a medium-severity vulnerability affecting IBM UrbanCode Deploy versions 6.2.7.0 through 7.2.3.1. An authenticated administrator with "Manage Security" permissions could recover credentials previously saved for LDAP searches. The CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N), indicating a network-based attack with low complexity, requiring high privileges, and resulting in high confidentiality impact. There is currently no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.7.0, < 6.2.7.18CPE matchmatch criteria | cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* | ||
>= 7.0.0.0, < 7.0.5.13CPE matchmatch criteria | cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* | ||
>= 7.1.0.0, < 7.1.2.9CPE matchmatch criteria | cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* | ||
>= 7.2.0.0, < 7.2.3.2CPE matchmatch criteria | cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* | ||
>= 6.2.7.0, < 6.2.7.17CPE match | cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.