CVE-2021-29753
Summary
| CVE | CVE-2021-29753 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-05 18:15:00 UTC |
| Updated | 2021-11-09 14:24:00 UTC |
| Description | IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Business Automation Workflow | 18.0.0.0 | All | All | All |
| Application | Ibm | Business Automation Workflow | 19.0.0.0 | All | All | All |
| Application | Ibm | Business Automation Workflow | 20.0.0.0 | All | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.0.0 | All | All | All |
| Application | Ibm | Business Process Manager | 8.5.0.0 | All | All | All |
| Application | Ibm | Business Process Manager | 8.6.0.0 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ibm-baw-cve202129753-info-disc (201919) | XF | exchange.xforce.ibmcloud.com | |
| Security Bulletin: Information disclosure vulnerability affect IBM Business Automation Workflow and IBM Business Process Manager (BPM) - CVE-2021-29753 | CONFIRM | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.