6.5

CVE-2021-38900

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version18.0.0.0
IbmBusiness Automation Workflow Version18.0.0.1
IbmBusiness Automation Workflow Version18.0.0.2
IbmBusiness Automation Workflow Version19.0.0.0
IbmBusiness Automation Workflow Version19.0.0.1
IbmBusiness Automation Workflow Version20.0.0.0
IbmBusiness Automation Workflow Version21.0.0.0 SwEdition-
IbmBusiness Process Manager Version8.5.0.0
IbmBusiness Process Manager Version8.6.0.0 Update- SwEdition-
IbmWorkflow Process Service Version21.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.451
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
psirt@us.ibm.com 4.9 1.2 3.6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N