First published: Mon Aug 21 2023(Updated: )
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <=21.0.0 - 21.0.7.1 | |
IBM Robotic Process Automation for Cloud Pak | <=21.0.0 - 21.0.7.1 | |
IBM Robotic Process Automation | >=21.0.0<=21.0.7.1 | |
IBM Robotic Process Automation for Cloud Pak | >=21.0.0<=21.0.7.1 | |
Redhat Openshift | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-40370.
The severity of CVE-2023-40370 is medium with a CVSS score of 5.3.
You can check if you are affected by CVE-2023-40370 by verifying that you have IBM Robotic Process Automation runtime version 21.0.0 through 21.0.7.1 installed.
To fix CVE-2023-40370, apply the patch provided by IBM for IBM Robotic Process Automation version 21.0.0 through 21.0.7.1.
You can find more information about CVE-2023-40370 on the IBM X-Force Exchange website.