CVE-2021-39046

MEDIUM

IBM Business Automation Workflow 18.0-21.0 and Business Process Manager 8.5-8.6 - Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6564387
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/214346

Scores

CVSS v3 4.9
EPSS 0.0014
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (11)
ibm/business_automation_workflow 18.0.0.0
ibm/business_automation_workflow 18.0.0.1
ibm/business_automation_workflow 18.0.0.2
ibm/business_automation_workflow 19.0.0.1
ibm/business_automation_workflow 19.0.0.2
ibm/business_automation_workflow 19.0.0.3
ibm/business_automation_workflow 20.0.0.1
ibm/business_automation_workflow 20.0.0.2
ibm/business_automation_workflow 21.0.2
ibm/business_process_manager 8.5
... and 1 more
Published Mar 18, 2022
Tracked Since Feb 18, 2026