
Severity
High
Analysis Summary
CVE-2021-29714
IBM Content Navigator could allow a malicious user to cause a denial of service due to improper input validation.
CVE-2021-20349
IBM Tivoli Workload Scheduler is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges.
Impact
- Denial of Service
- Unauthorized Access
Affected Vendors
IBM
Affected Products
- IBM Content Navigator 3.0.CD
- IBM Workload Scheduler 9.4
- IBM Workload Scheduler 9.5
Remediation
Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.