Lucene search

K
ibmIBM1819C8983291CD2F32C8604D19FCEE86E922F3941B16358D387355D914982172
HistoryJun 27, 2023 - 7:36 p.m.

Security Bulletin: A vulnerability in the Oracle Data Provider may affect IBM Robotic Process Automation and result in an attacker gaining elevated privileges (CVE-2023-21893).

2023-06-2719:36:42
www.ibm.com
16
oracle data provider
ibm robotic process automation
sql server
database connectivity
cve-2023-21893
vulnerability
elevated privileges
oracle database server
remote attacker
error
.net component
web site
control
system
cvss
ibm
cloud pak
versions
remediation
download
instructions
update
upgrading
openshift container platform

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

75.6%

Summary

Oracle Data Provider is used by IBM Robotic Process Automation as part of SQL Server database connectivity. (CVE-2023-21893).

Vulnerability Details

CVEID:CVE-2023-21893
**DESCRIPTION:**Oracle Database Server could allow a remote attacker to gain elevated privileges on the system, caused by an error in the Oracle Data Provider for .NET component. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to take control of the system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/244946 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation 21.0 21.0.0 - 21.0.7.4
IBM Robotic Process Automation 23.0 23.0.0 - 23.0.6
IBM Robotic Process Automation for Cloud Pak 21.0 21.0.0 - 21.0.7.4
IBM Robotic Process Automation for Cloud Pak 23.0 23.0.0 - 23.0.6

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation 21.0.0 - 21.0.7.4 Download 21.0.7.5 or higher, and follow instructions.
IBM Robotic Process Automation 23.0.0 - 23.0.6 Download 23.0.7 or higher, and follow instructions.
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.4 Update to 21.0.7.5 or higher using the following instructions.
IBM Robotic Process Automation for Cloud Pak 23.0.0 - 23.0.6 Update to 23.0.7 or higher using the following instructions.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.7.4
OR
ibmrobotic_process_automationMatch23.0.0
OR
ibmrobotic_process_automationMatch23.0.6
VendorProductVersionCPE
ibmrobotic_process_automation21.0.0cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.7.4cpe:2.3:a:ibm:robotic_process_automation:21.0.7.4:*:*:*:*:*:*:*
ibmrobotic_process_automation23.0.0cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation23.0.6cpe:2.3:a:ibm:robotic_process_automation:23.0.6:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

75.6%

Related for 1819C8983291CD2F32C8604D19FCEE86E922F3941B16358D387355D914982172