First published: Sat Feb 11 2023(Updated: )
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.6 | |
IBM Robotic Process Automation as a Service | <21.0.6 | |
IBM Robotic Process Automation for Cloud Pak | >=21.0.1<21.0.6 | |
<=21.0.1 - 21.0.5 | ||
<=< 21.0.6 | ||
<=< 21.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-25680.
The severity of CVE-2023-25680 is medium (6.5).
IBM Robotic Process Automation versions 21.0.1 through 21.0.5, IBM Robotic Process Automation as a Service versions up to 21.0.6, and IBM Robotic Process Automation for Cloud Pak versions 21.0.1 through 21.0.6 are affected by CVE-2023-25680.
To fix CVE-2023-25680, upgrade to IBM Robotic Process Automation version 21.0.6, IBM Robotic Process Automation as a Service version 21.0.6, or IBM Robotic Process Automation for Cloud Pak version 21.0.6.
You can find more information about CVE-2023-25680 at the following references: [IBM X-Force ID: 247032](https://exchange.xforce.ibmcloud.com/vulnerabilities/247032) and [IBM support page](https://www.ibm.com/support/pages/node/6962207).