First published: Mon Aug 21 2023(Updated: )
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | >=21.0.0<=21.0.7.1 | |
IBM Robotic Process Automation | =23.0.0 | |
IBM Robotic Process Automation | =23.0.1 | |
Redhat Openshift | ||
Microsoft Windows | ||
<=21.0.0 - 21.0.7.1, 23.0.0 - 23.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-38734.
The title of the vulnerability is 'IBM Robotic Process Automation is vulnerable to incorrect privilege assignment when importing users from an LDAP directory.'
IBM Robotic Process Automation versions 21.0.0 through 21.0.7.1, and 23.0.0 through 23.0.1 are affected.
The severity rating of this vulnerability is critical with a score of 9.8.
To fix this vulnerability, update IBM Robotic Process Automation to a version that is not affected (beyond 23.0.1).