Lucene search

K
cveIbmCVE-2023-23476
HistoryAug 02, 2023 - 3:15 p.m.

CVE-2023-23476

2023-08-0215:15:10
CWE-863
ibm
web.nvd.nist.gov
2482
ibm
rpa
robotic process automation
cve-2023-23476
data access
authorization validation

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

26.1%

IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.

Affected configurations

Nvd
Vulners
Node
ibmrobotic_process_automationRange21.0.023.0.0
OR
ibmrobotic_process_automation_for_cloud_pakRange21.0.023.0.0
VendorProductVersionCPE
ibmrobotic_process_automation*cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*
ibmrobotic_process_automation_for_cloud_pak*cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Robotic Process Automation",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "21.0.7.latest",
        "status": "affected",
        "version": "21.0.0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Robotic Process Automation for Cloud Pak",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "21.0.7.latest",
        "status": "affected",
        "version": "21.0.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

26.1%

Related for CVE-2023-23476