CVE-2021-38900: Medium severity ibm workflow process service vulnerability
IBM Business Automation Workflow could allow a privileged user to obtain highly sensitive information due to improper access controls.
Other sources
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38900.
What is the severity of CVE-2021-38900?
The severity of CVE-2021-38900 is medium.
Which products are affected by CVE-2021-38900?
IBM Business Process Manager 8.5 and 8.6, IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0, and IBM ICP4A - Workflow Process Services versions up to 21.0.2 are affected by CVE-2021-38900.
What can a privileged user do with CVE-2021-38900?
A privileged user can obtain highly sensitive information due to improper access controls with CVE-2021-38900.
Where can I find more information about CVE-2021-38900?
You can find more information about CVE-2021-38900 on the IBM X-Force ID page or the IBM support pages.