CVE-2023-38734: IBM Robotic Process Automation privilege escalation
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.
Other sources
IBM Robotic Process Automation is vulnerable to incorrect privilege assignment when importing users from an LDAP directory.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-38734.
What is the title of the vulnerability?
The title of the vulnerability is 'IBM Robotic Process Automation is vulnerable to incorrect privilege assignment when importing users from an LDAP directory.'
What products are affected by this vulnerability?
IBM Robotic Process Automation versions 21.0.0 through 21.0.7.1, and 23.0.0 through 23.0.1 are affected.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is critical with a score of 9.8.
How can I fix this vulnerability?
To fix this vulnerability, update IBM Robotic Process Automation to a version that is not affected (beyond 23.0.1).