CVE-2021-38900

Description

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.247

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.0Windows
Vulnerabilities CVE-2021-29753,CVE-2021-29835,CVE-2021-38893,CVE-2021-38900 are affected in IBM Business Automation Workflow 21.0.0.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234