SB2025121520 - Multiple vulnerabilities in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 



SB2025121520 - Multiple vulnerabilities in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)

Published: December 15, 2025

Security Bulletin ID SB2025121520
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Path traversal (CVE-ID: CVE-2025-55752)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences passed via Rewrite Valve. A remote attacker can send a specially crafted HTTP PUT request and write arbitrary files to the server, leading to remote code execution. 


2) Resource exhaustion (CVE-ID: CVE-2025-61795)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling errors while processing multipart upload. Depending on JVM settings, application memory usage and application load, it is possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS.


Remediation

Install update from vendor's website.