{
   "CVE_data_meta" : {
      "ASSIGNER" : "psirt@us.ibm.com",
      "ID" : "CVE-2021-29697",
      "DATE_PUBLIC" : "2021-07-30T00:00:00",
      "STATE" : "PUBLIC"
   },
   "data_type" : "CVE",
   "description" : {
      "description_data" : [
         {
            "lang" : "eng",
            "value" : "IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system."
         }
      ]
   },
   "data_version" : "4.0",
   "problemtype" : {
      "problemtype_data" : [
         {
            "description" : [
               {
                  "value" : "Obtain Information",
                  "lang" : "eng"
               }
            ]
         }
      ]
   },
   "affects" : {
      "vendor" : {
         "vendor_data" : [
            {
               "product" : {
                  "product_data" : [
                     {
                        "version" : {
                           "version_data" : [
                              {
                                 "version_value" : "1.6.0.0"
                              },
                              {
                                 "version_value" : "1.5.0.1"
                              },
                              {
                                 "version_value" : "1.5.0.0"
                              },
                              {
                                 "version_value" : "1.6.0.1"
                              },
                              {
                                 "version_value" : "1.7.0.0"
                              },
                              {
                                 "version_value" : "1.7.1.0"
                              }
                           ]
                        },
                        "product_name" : "Cloud Pak for Security"
                     }
                  ]
               },
               "vendor_name" : "IBM"
            }
         ]
      }
   },
   "data_format" : "MITRE",
   "references" : {
      "reference_data" : [
         {
            "refsource" : "CONFIRM",
            "name" : "https://www.ibm.com/support/pages/node/6476940",
            "url" : "https://www.ibm.com/support/pages/node/6476940",
            "title" : "IBM Security Bulletin 6476940 (Cloud Pak for Security)"
         },
         {
            "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/200598",
            "title" : "X-Force Vulnerability Report",
            "refsource" : "XF",
            "name" : "ibm-cp4s-cve202129697-info-disc (200598)"
         }
      ]
   },
   "impact" : {
      "cvssv3" : {
         "BM" : {
            "SCORE" : "4.900",
            "AC" : "L",
            "A" : "N",
            "AV" : "N",
            "S" : "U",
            "PR" : "H",
            "I" : "N",
            "UI" : "N",
            "C" : "H"
         },
         "TM" : {
            "RC" : "C",
            "RL" : "O",
            "E" : "U"
         }
      }
   }
}
