PT-2022-23208 · Blue Prism · Blue Prism Enterprise
Published
2022-08-25
·
Updated
2023-08-08
·
CVE-2022-36120
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blue Prism Enterprise versions 6.0 through 7.01
Description
The issue allows an authenticated user to reverse engineer the software and circumvent access controls for the
getChartData administrative function in a misconfigured environment that exposes the Blue Prism Application server. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.Recommendations
For Blue Prism Enterprise versions 6.0 through 7.01, consider restricting access to the
getChartData administrative function to prevent abuse and limit the execution of MSSQL stored procedures.
As a temporary workaround, consider disabling the getChartData method until a proper configuration or patch is available to prevent the circumvention of access controls.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blue Prism Enterprise