PT-2021-18451 · Ibm · Ibm Business Process Manager+1

Published

2021-06-28

·

Updated

2022-07-12

·

CVE-2021-29751

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Business Automation Workflow versions 18.0 through 20.0 IBM Business Process Manager versions 8.5 through 8.6
Description The issue allows an authenticated user to obtain sensitive information about another user under nondefault configurations.
Recommendations For IBM Business Automation Workflow versions 18.0 through 20.0, update to a version that includes the fix for this issue. For IBM Business Process Manager versions 8.5 through 8.6, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive user information until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29751

Affected Products

Ibm Business Automation Workflow
Ibm Business Process Manager