Vulnerability Description
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Business Automation Workflow | 18.0.0.0 |
| Ibm | Business Process Manager | 8.5.0.0 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/201919VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6513703Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/201919VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6513703Vendor Advisory
FAQ
What is CVE-2021-29753?
CVE-2021-29753 is a vulnerability with a CVSS score of 5.9 (MEDIUM). IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to una...
How severe is CVE-2021-29753?
CVE-2021-29753 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29753?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Business Automation Workflow, Ibm Business Process Manager.