PT-2019-12535 · Blue Prism · Blue Prism Robotic Process Automation

Published

2019-05-24

·

Updated

2020-08-24

·

CVE-2019-11875

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blue Prism Robotic Process Automation version 6.4.0.8445
Description A vulnerability in access control exists, allowing for privilege escalation. This issue can be exploited to abuse the application for fraud or unauthorized access to certain information. The attack requires a valid user account to connect to the Blue Prism server, but no specific permissions are needed for the associated roles. An attacker can modify application files to grant full permissions on the client side and, in a test environment or their own instance, grant themselves full privileges on the server side. This enables the creation of a process with malicious behavior, which can be exported and then imported as a release, overwriting existing processes in the database. The bots will eventually execute the malicious process, as the server does not check user permissions for these actions. Possible scenarios include changing bank accounts or setting passwords.
Recommendations For Blue Prism Robotic Process Automation version 6.4.0.8445, consider restricting access to the application's modification capabilities to prevent privilege escalation until a patch is available. As a temporary workaround, monitor all changes to processes and releases in the database to detect potential malicious activity.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11875

Affected Products

Blue Prism Robotic Process Automation