IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
2021-06-28T16:15:08.430
2024-11-21T06:01:44.267
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | business_automation_workflow | 18.0.0.0 | Yes |
Application | ibm | business_automation_workflow | 19.0.0.0 | Yes |
Application | ibm | business_automation_workflow | 20.0.0.0 | Yes |
Application | ibm | business_process_manager | 8.5.0.0 | Yes |
Application | ibm | business_process_manager | 8.6.0.0 | Yes |