IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/6513703 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/201919 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-11-05 11:15
Updated : 2021-11-09 06:24
NVD link : CVE-2021-29753
Mitre link : CVE-2021-29753
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
ibm
- business_automation_workflow
- business_process_manager