CVE-2023-45189: IBM Robotic Process Automation information disclosure
A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.
Other sources
A vulnerability in IBM Robotic Process Automation may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45189?
The severity of CVE-2023-45189 is medium with a CVSS score of 6.5.
What is affected by CVE-2023-45189?
IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak versions 21.0.0 through 21.0.7.10 and 23.0.0 through 23.0.10 are affected.
How can an attacker exploit CVE-2023-45189?
This vulnerability is difficult to exploit, but a low privileged attacker could programmatically access client vault credentials.
Are there any fixes available for CVE-2023-45189?
Yes, IBM has released fixes for this vulnerability. Refer to the IBM Support page for more information.
Where can I find more information about CVE-2023-45189?
You can find more information about CVE-2023-45189 on the IBM Support page and the IBM X-Force Exchange.