First published: Fri Jun 25 2021(Updated: )
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =19.0.0.0 | |
IBM Business Automation Workflow | =20.0.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.6.0.0 | |
<=V20.0V19.0V18.0 | ||
<=V8.6V8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Business Automation Workflow vulnerability is CVE-2021-29751.
The severity level of CVE-2021-29751 is medium, with a severity value of 4.3.
This vulnerability affects IBM Business Automation Workflow versions 18.0, 19.0, and 20.0.
This vulnerability affects IBM Business Process Manager versions 8.5 and 8.6.
An authenticated user can exploit this vulnerability under nondefault configurations to obtain sensitive information about another user.