Show plain JSON{"containers": {"cna": {"affected": [{"product": "Business Process Manager", "vendor": "IBM", "versions": [{"status": "affected", "version": "8.5"}, {"status": "affected", "version": "8.6"}]}, {"product": "Business Automation Workflow", "vendor": "IBM", "versions": [{"status": "affected", "version": "18.0"}, {"status": "affected", "version": "19.0"}, {"status": "affected", "version": "20.0"}]}, {"product": "Cloud Pak for Automation", "vendor": "IBM", "versions": [{"status": "affected", "version": "20.0.3.IF002"}, {"status": "affected", "version": "21.0.1"}]}], "datePublic": "2021-06-25T00:00:00", "descriptions": [{"lang": "en", "value": "IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779."}], "metrics": [{"cvssV3_0": {"attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 3.1, "baseSeverity": "LOW", "confidentialityImpact": "LOW", "exploitCodeMaturity": "UNPROVEN", "integrityImpact": "NONE", "privilegesRequired": "LOW", "remediationLevel": "OFFICIAL_FIX", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 2.7, "temporalSeverity": "LOW", "userInteraction": "NONE", "vectorString": "CVSS:3.0/C:L/UI:N/S:U/AV:N/PR:L/I:N/AC:H/A:N/E:U/RL:O/RC:C", "version": "3.0"}}], "problemTypes": [{"descriptions": [{"description": "Obtain Information", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2021-06-28T15:55:25", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm"}, "references": [{"tags": ["x_refsource_CONFIRM"], "url": "https://www.ibm.com/support/pages/node/6465127"}, {"tags": ["x_refsource_CONFIRM"], "url": "https://www.ibm.com/support/pages/node/6467055"}, {"name": "ibm-baw-cve202129751-info-disc (201779)", "tags": ["vdb-entry", "x_refsource_XF"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/201779"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2021-06-25T00:00:00", "ID": "CVE-2021-29751", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Business Process Manager", "version": {"version_data": [{"version_value": "8.5"}, {"version_value": "8.6"}]}}, {"product_name": "Business Automation Workflow", "version": {"version_data": [{"version_value": "18.0"}, {"version_value": "19.0"}, {"version_value": "20.0"}]}}, {"product_name": "Cloud Pak for Automation", "version": {"version_data": [{"version_value": "20.0.3.IF002"}, {"version_value": "21.0.1"}]}}]}, "vendor_name": "IBM"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779."}]}, "impact": {"cvssv3": {"BM": {"A": "N", "AC": "H", "AV": "N", "C": "L", "I": "N", "PR": "L", "S": "U", "UI": "N"}, "TM": {"E": "U", "RC": "C", "RL": "O"}}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "Obtain Information"}]}]}, "references": {"reference_data": [{"name": "https://www.ibm.com/support/pages/node/6465127", "refsource": "CONFIRM", "title": "IBM Security Bulletin 6465127 (Cloud Pak for Automation)", "url": "https://www.ibm.com/support/pages/node/6465127"}, {"name": "https://www.ibm.com/support/pages/node/6467055", "refsource": "CONFIRM", "title": "IBM Security Bulletin 6467055 (Business Automation Workflow)", "url": "https://www.ibm.com/support/pages/node/6467055"}, {"name": "ibm-baw-cve202129751-info-disc (201779)", "refsource": "XF", "title": "X-Force Vulnerability Report", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/201779"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T22:18:02.690Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://www.ibm.com/support/pages/node/6465127"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://www.ibm.com/support/pages/node/6467055"}, {"name": "ibm-baw-cve202129751-info-disc (201779)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/201779"}]}]}, "cveMetadata": {"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2021-29751", "datePublished": "2021-06-28T15:55:25.283945Z", "dateReserved": "2021-03-31T00:00:00", "dateUpdated": "2024-09-17T02:47:11.003Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}