Cross-Site Scripting Vulnerability in IBM Business Automation Workflow and Cloud Pak for Automation
CVE-2021-29775
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 28 June 2021
What is CVE-2021-29775?
IBM Business Automation Workflow and IBM Cloud Pak for Automation are susceptible to a cross-site scripting vulnerability that allows attackers to inject arbitrary JavaScript code into the Web UI. This can lead to unauthorized manipulation of the user interface and potentially expose sensitive information such as user credentials within a trusted session. Users should be aware of this risk and implement necessary patches to secure their deployments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Automation Workflow 18.0.0.0
Business Automation Workflow 18.0.0.1
Business Automation Workflow 18.0.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved