First published: Wed Mar 15 2023(Updated: )
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | >=21.0.1<21.0.7.1 | |
IBM Robotic Process Automation | >=23.0.0<23.0.2 | |
IBM Robotic Process Automation as a Service | <23.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22591 is low with a severity value of 3.2.
CVE-2023-22591 affects IBM Robotic Process Automation versions 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1, as well as IBM Robotic Process Automation as a Service version up to 23.0.2.
CVE-2023-22591 allows a user with physical access to the system to retain session tokens even after a password reset.
To fix CVE-2023-22591, it is recommended to update IBM Robotic Process Automation to versions 21.0.7.1 or later, and IBM Robotic Process Automation as a Service to version 23.0.3 or later.
You can find more information about CVE-2023-22591 at the IBM X-Force ID 243710 page and the IBM support page.