{"api_version":"1","generated_at":"2026-07-23T20:06:00+00:00","cve":"CVE-2016-0373","urls":{"html":"https://cve.report/CVE-2016-0373","api":"https://cve.report/api/cve/CVE-2016-0373.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-0373","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-0373"},"summary":{"title":"CVE-2016-0373","description":"IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2018-08-30 16:29:00","updated_at":"2019-10-09 23:16:00"},"problem_types":["CWE-285"],"metrics":[],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219","name":"http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Multiple UCD REST endpoints allow unauthorized users to view data (CVE-2016-0373)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/112119","name":"ibm-ucd-cve20160373-info-disc(112119)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-0373","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0373","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"373","vulnerable":"1","versionEndIncluding":"6.2.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"urbancode_deploy","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2016-11-14T00:00:00","ID":"CVE-2016-0373","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"UrbanCode Deploy","version":{"version_data":[{"version_value":"6.1.0.2"},{"version_value":"6.0"},{"version_value":"6.0.1"},{"version_value":"6.0.1.1"},{"version_value":"6.0.1.2"},{"version_value":"6.0.1.3"},{"version_value":"6.0.1.4"},{"version_value":"6.0.1.5"},{"version_value":"6.0.1.6"},{"version_value":"6.1"},{"version_value":"6.1.0.1"},{"version_value":"6.1.0.3"},{"version_value":"6.0.1.7"},{"version_value":"6.0.1.8"},{"version_value":"6.1.0.4"},{"version_value":"6.1.1"},{"version_value":"6.1.1.1"},{"version_value":"6.1.1.2"},{"version_value":"6.1.1.3"},{"version_value":"6.1.1.4"},{"version_value":"6.1.1.5"},{"version_value":"6.0.1.9"},{"version_value":"6.1.1.6"},{"version_value":"6.1.1.7"},{"version_value":"6.1.2"},{"version_value":"6.0.1.10"},{"version_value":"6.0.1.11"},{"version_value":"6.1.1.8"},{"version_value":"6.1.3"},{"version_value":"6.1.3.1"},{"version_value":"6.2"},{"version_value":"6.2.0.1"},{"version_value":"6.0.1.12"},{"version_value":"6.1.3.2"},{"version_value":"6.2.0.2"},{"version_value":"6.2.1"},{"version_value":"6.0.1.13"},{"version_value":"6.2.1.1"},{"version_value":"6.0.1.14"},{"version_value":"6.1.3.3"},{"version_value":"6.2.2"},{"version_value":"6.2.2.1"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"H","AV":"N","C":"L","I":"N","PR":"L","S":"U","SCORE":"3.100","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219"},{"name":"ibm-ucd-cve20160373-info-disc(112119)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/112119"}]}},"nvd":{"publishedDate":"2018-08-30 16:29:00","lastModifiedDate":"2019-10-09 23:16:00","problem_types":["CWE-285"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndIncluding":"6.2.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"373","Ordinal":"85929","Title":"CVE-2016-0373","CVE":"CVE-2016-0373","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"373","Ordinal":"1","NoteData":"IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"373","Ordinal":"2","NoteData":"2018-08-30","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"373","Ordinal":"3","NoteData":"2018-08-30","Type":"Other","Title":"Modified"}]}}}