CVE-2023-43058: IBM Robotic Process Automation privilege escalation
Published Oct 4, 2023
·Updated
IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.
Other sources
IBM Robotic Process Automation is vulnerable to privilege escalation that affects ownership of projects.
Affected Software
5 affected componentsFixes available
IBM Robotic Process Automation for Cloud Pak<=23.0.9
IBM Robotic Process Automation<=23.0.9
IBM Robotic Process Automation=23.0.9
IBM Robotic Process Automation for Cloud Pak=23.0.9
redhat Openshift
Remediation
Patch Available
Event History
Oct 4, 2023
CVE Published
12:00 AM
Oct 6, 2023
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43058.
2
What software is affected by this vulnerability?
IBM Robotic Process Automation 23.0.9, IBM Robotic Process Automation for Cloud Pak 23.0.9, and other related versions are affected by this vulnerability.
3
What is the severity of CVE-2023-43058?
The severity of CVE-2023-43058 is critical with a CVSS score of 9.8.
4
How does this vulnerability affect users?
This vulnerability allows for privilege escalation that affects the ownership of projects in IBM Robotic Process Automation.
5
How can I fix CVE-2023-43058?
To fix CVE-2023-43058, apply the relevant patch provided by IBM.