First published: Wed Nov 01 2023(Updated: )
A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation for Cloud Pak | <=21.0.0 - 21.0.7.10, 23.0.0 - 23.0.10 | |
IBM Robotic Process Automation | <=21.0.0 - 21.0.7.10, 23.0.0 - 23.0.10 | |
IBM Robotic Process Automation for Cloud Pak | >=21.0.0<=21.0.7 | |
IBM Robotic Process Automation for Cloud Pak | >=23.0.0<=23.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-45189 is medium with a CVSS score of 6.5.
IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak versions 21.0.0 through 21.0.7.10 and 23.0.0 through 23.0.10 are affected.
This vulnerability is difficult to exploit, but a low privileged attacker could programmatically access client vault credentials.
Yes, IBM has released fixes for this vulnerability. Refer to the IBM Support page for more information.
You can find more information about CVE-2023-45189 on the IBM Support page and the IBM X-Force Exchange.