Vulnerability Details CVE-2021-29859
IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user with physical access to the system to perform unauthorized actions or obtain sensitive information due to insufficient validation and recvocation another user logouting out. IBM X-Force ID: 206081.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.8%
CVSS Severity
CVSS v3 Score 3.5
CVSS v2 Score 4.6
Products affected by CVE-2021-29859
-
cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1
-
cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.2
-
cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.3