First published: Tue Aug 01 2023(Updated: )
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | >=21.0.0<23.0.0 | |
IBM Robotic Process Automation for Cloud Pak | >=21.0.0<23.0.0 | |
IBM Robotic Process Automation | <=21.0.0-21.0.7.latest | |
IBM Robotic Process Automation for Cloud Pak | <=21.0.0-21.0.7.latest |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23476 is medium (6.5).
CVE-2023-23476 allows unauthorized access to data due to insufficient authorization validation on some API routes in IBM Robotic Process Automation 21.0.0 through 21.0.7.latest.
Yes, IBM Robotic Process Automation versions 21.0.0 through 21.0.7.latest are affected by CVE-2023-23476.
To fix CVE-2023-23476 in IBM Robotic Process Automation, apply the necessary security updates provided by IBM.
You can find more information about CVE-2023-23476 on the IBM X-Force ID: 245425.