First published: Mon Jul 01 2019(Updated: )
IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation with Automation Anywhere | >=11.0.0.0<11.0.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4298 has a medium severity rating due to the potential for unauthorized access through a high-privileged PostgreSQL account.
To remediate CVE-2019-4298, restrict the usage of the high privileged PostgreSQL account or downgrade to a less privileged account for database access.
CVE-2019-4298 affects users of IBM Robotic Process Automation with Automation Anywhere version 11 prior to 11.0.0.5.
The potential risks of CVE-2019-4298 include unauthorized user actions on the database leading to data integrity issues.
A patch or update would typically be included in newer releases of IBM Robotic Process Automation, particularly those beyond version 11.0.0.5.