{"api_version":"1","generated_at":"2026-07-23T23:41:26+00:00","cve":"CVE-2021-29758","urls":{"html":"https://cve.report/CVE-2021-29758","api":"https://cve.report/api/cve/CVE-2021-29758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-29758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-29758"},"summary":{"title":"CVE-2021-29758","description":"IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2021-10-06 17:15:00","updated_at":"2022-05-03 16:04:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/pages/node/6495969","name":"https://www.ibm.com/support/pages/node/6495969","refsource":"CONFIRM","tags":[],"title":"Security Bulletin: Access Control Vulnerabilities Affects the Dashboard User Interface of IBM Sterling B2B Integrator","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/202169","name":"ibm-sterling-cve202129758-access-control (202169)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-29758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"29758","vulnerable":"1","versionEndIncluding":"6.1.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sterling_b2b_integrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"standard","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_format":"MITRE","problemtype":{"problemtype_data":[{"description":[{"value":"Gain Access","lang":"eng"}]}]},"references":{"reference_data":[{"url":"https://www.ibm.com/support/pages/node/6495969","refsource":"CONFIRM","name":"https://www.ibm.com/support/pages/node/6495969","title":"IBM Security Bulletin 6495969 (Sterling B2B Integrator)"},{"title":"X-Force Vulnerability Report","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/202169","refsource":"XF","name":"ibm-sterling-cve202129758-access-control (202169)"}]},"description":{"description_data":[{"value":"IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.","lang":"eng"}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Sterling B2B Integrator","version":{"version_data":[{"version_value":"6.0.0.0"},{"version_value":"5.2.0.0"},{"version_value":"6.0.1.0"},{"version_value":"6.1.0.0"},{"version_value":"6.0.3.4"},{"version_value":"6.1.0.3"},{"version_value":"5.2.6.5_4"},{"version_value":"6.0.0.6"}]}}]}}]}},"impact":{"cvssv3":{"BM":{"C":"N","AC":"L","S":"U","I":"L","AV":"N","UI":"N","SCORE":"4.300","PR":"L","A":"N"},"TM":{"RC":"C","E":"U","RL":"O"}}},"data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-29758","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2021-10-05T00:00:00","STATE":"PUBLIC"},"data_type":"CVE"},"nvd":{"publishedDate":"2021-10-06 17:15:00","lastModifiedDate":"2022-05-03 16:04:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:standard:*:*:*","versionStartIncluding":"5.2.0.0","versionEndIncluding":"6.1.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"29758","Ordinal":"204988","Title":"CVE-2021-29758","CVE":"CVE-2021-29758","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"29758","Ordinal":"1","NoteData":"IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"29758","Ordinal":"2","NoteData":"2021-10-06","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"29758","Ordinal":"3","NoteData":"2021-10-06","Type":"Other","Title":"Modified"}]}}}