CVE-2021-29751

Severity
4.3MEDIUM
EPSS
0.2%
top 54.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateMay 24

Description

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5ibm/business_process_manager8.5, 8.6+1
NVDibm/business_process_manager8.5.0.0, 8.6.0.0+1
CVEListV5ibm/business_automation_workflow18.0, 19.0, 20.0+2
NVDibm/business_automation_workflow18.0.0.0, 19.0.0.0, 20.0.0.0+2
CVEListV5ibm/cloud_pak_for_automation20.0.3.IF002, 21.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5w9g-vrj4-xwgh: IBM Business Automation Workflow 182022-05-24
CVEList
CVE-2021-29751: IBM Business Automation Workflow 182021-06-28
CVE-2021-29751 (MEDIUM CVSS 4.3) | IBM Business Automation Workflow 18 | cvebase.io