CVE-2023-25680: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
Other sources
IBM Robotic Process Automation is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-25680.
What is the severity of CVE-2023-25680?
The severity of CVE-2023-25680 is medium (6.5).
Which software is affected by CVE-2023-25680?
IBM Robotic Process Automation versions 21.0.1 through 21.0.5, IBM Robotic Process Automation as a Service versions up to 21.0.6, and IBM Robotic Process Automation for Cloud Pak versions 21.0.1 through 21.0.6 are affected by CVE-2023-25680.
How can I fix CVE-2023-25680?
To fix CVE-2023-25680, upgrade to IBM Robotic Process Automation version 21.0.6, IBM Robotic Process Automation as a Service version 21.0.6, or IBM Robotic Process Automation for Cloud Pak version 21.0.6.
Where can I find more information about CVE-2023-25680?
You can find more information about CVE-2023-25680 at the following references: [IBM X-Force ID: 247032](https://exchange.xforce.ibmcloud.com/vulnerabilities/247032) and [IBM support page](https://www.ibm.com/support/pages/node/6962207).