CVE-2021-29701: Medium severity ibm engineering workflow management vulnerability
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.
Other sources
IBM Engineering Workflow Management could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-29701.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Engineering Workflow Management could allow an authenticated attacker to obtain sensitive information.'
What software is affected by this vulnerability?
IBM Engineering Workflow Management versions 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert versions 6.0.6 and 6.0.6.1 are affected by this vulnerability.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a CVSS score of 4.3.
How can an attacker exploit this vulnerability?
An authenticated attacker can exploit this vulnerability by obtaining sensitive information from build definitions, which can aid in further attacks against the system.