PT-2023-5437 · Ibm · Ibm Robotic Process Automation

Mariana Penna

·

Publicado

2023-08-22

·

Atualizado

2023-08-26

·

CVE-2023-40370

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation versions 21.0.0 through 21.0.7.1
Description The issue is related to information disclosure of script content in IBM Robotic Process Automation when the remote REST request computer policy is enabled. This could allow a remote attacker to disclose protected information.
Recommendations For versions 21.0.0 through 21.0.7.1, consider disabling the remote REST request computer policy as a temporary workaround until a patch is available. Restrict access to sensitive script content to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06067
CVE-2023-40370

Produtos afetados

Ibm Robotic Process Automation