4
CVSSv2

CVE-2021-38900

Published: 21/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm business process manager 8.5.0.0

ibm business automation workflow 18.0.0.1

ibm business automation workflow 18.0.0.0

ibm business automation workflow 18.0.0.2

ibm business process manager 8.6.0.0

ibm business automation workflow 19.0.0.0

ibm business automation workflow 20.0.0.0

ibm business automation workflow 19.0.0.1

ibm business automation workflow 21.0.0.0

ibm workflow process service 21.0.2