CVE-2021-29753 Information

Description

IBM Business Automation Workflow 18. 19 20 21 and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://www.ibm.com/support/pages/node/6513703 https://exchange.xforce.ibmcloud.com/vulnerabilities/201919

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.9

Share on: