Lucene search

K
cvelistIbmCVELIST:CVE-2021-29859
HistoryMay 02, 2022 - 4:55 p.m.

CVE-2021-29859

2022-05-0216:55:10
ibm
www.cve.org
2
ibm icp4a
user management
security issue
ibm cloud pak
business automation
validation
revocation

CVSS3

3.5

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

20.6%

IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user with physical access to the system to perform unauthorized actions or obtain sensitive information due to insufficient validation and recvocation another user logouting out. IBM X-Force ID: 206081.

CNA Affected

[
  {
    "product": "Cloud Pak for Business Automation",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "18.0.0"
      },
      {
        "status": "affected",
        "version": "18.0.1"
      },
      {
        "status": "affected",
        "version": "18.0.2"
      },
      {
        "status": "affected",
        "version": "19.0.1"
      },
      {
        "status": "affected",
        "version": "19.0.2"
      },
      {
        "status": "affected",
        "version": "19.0.3"
      },
      {
        "status": "affected",
        "version": "20.0.1"
      },
      {
        "status": "affected",
        "version": "20.0.2"
      },
      {
        "status": "affected",
        "version": "20.0.3"
      },
      {
        "status": "affected",
        "version": "21.0.1"
      },
      {
        "status": "affected",
        "version": "21.0.2"
      },
      {
        "status": "affected",
        "version": "21.0.3"
      }
    ]
  }
]

CVSS3

3.5

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

20.6%

Related for CVELIST:CVE-2021-29859