CVE-2021-20349

EUVD-2021-7767
IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 194599.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
ibmCNA
5.9 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AC:L/AV:L/S:U/UI:N/A:L/I:L/C:L/PR:N/RC:C/E:U/RL:O
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
ibmtivoli_workload_scheduler
9.4
ibmtivoli_workload_scheduler
9.5
𝑥
= Vulnerable software versions