PT-2023-5437 · Ibm · Ibm Robotic Process Automation

Mariana Penna

·

Published

2023-08-22

·

Updated

2023-08-26

·

CVE-2023-40370

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation versions 21.0.0 through 21.0.7.1
Description The issue is related to information disclosure of script content in IBM Robotic Process Automation when the remote REST request computer policy is enabled. This could allow a remote attacker to disclose protected information.
Recommendations For versions 21.0.0 through 21.0.7.1, consider disabling the remote REST request computer policy as a temporary workaround until a patch is available. Restrict access to sensitive script content to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06067
CVE-2023-40370

Affected Products

Ibm Robotic Process Automation