CVE-2023-40370: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470.
Other sources
IBM Robotic Process Automation runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40370.
What is the severity of CVE-2023-40370?
The severity of CVE-2023-40370 is medium with a CVSS score of 5.3.
How can I check if I am affected by CVE-2023-40370?
You can check if you are affected by CVE-2023-40370 by verifying that you have IBM Robotic Process Automation runtime version 21.0.0 through 21.0.7.1 installed.
How do I fix CVE-2023-40370?
To fix CVE-2023-40370, apply the patch provided by IBM for IBM Robotic Process Automation version 21.0.0 through 21.0.7.1.
Where can I find more information about CVE-2023-40370?
You can find more information about CVE-2023-40370 on the IBM X-Force Exchange website.