CVE-2023-23476: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.
Other sources
IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23476?
The severity of CVE-2023-23476 is medium (6.5).
How does CVE-2023-23476 impact IBM Robotic Process Automation?
CVE-2023-23476 allows unauthorized access to data due to insufficient authorization validation on some API routes in IBM Robotic Process Automation 21.0.0 through 21.0.7.latest.
Is IBM Robotic Process Automation affected by CVE-2023-23476?
Yes, IBM Robotic Process Automation versions 21.0.0 through 21.0.7.latest are affected by CVE-2023-23476.
What can be done to fix CVE-2023-23476 in IBM Robotic Process Automation?
To fix CVE-2023-23476 in IBM Robotic Process Automation, apply the necessary security updates provided by IBM.
Where can I find more information about CVE-2023-23476?
You can find more information about CVE-2023-23476 on the IBM X-Force ID: 245425.