Lucene search

K
ibmIBM386277663F598A3E1F69BD1883C92203ED54D4738A64A8D513983D9EB7D62F8B
HistoryAug 21, 2023 - 4:41 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to information disclosure of script content (CVE-2023-40370)

2023-08-2116:41:32
www.ibm.com
13
ibm
robotic process automation
vulnerability
disclosure
information
script content
cve-2023-40370
cvss
21.0.0 - 21.0.7.1
cloud pak
remediation
fix

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

24.0%

Summary

IBM Robotic Process Automation runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled.

Vulnerability Details

CVEID:CVE-2023-40370
**DESCRIPTION:**IBM Robotic Process Automation runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/263470 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation 21.0.0 - 21.0.7.1
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation 21.0.0 - 21.0.7.1 Download 21.0.7.2 or higher and follow these instructions.
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.1 Update to 21.0.7.2 or higher using the following instructions.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.7.1
VendorProductVersionCPE
ibmrobotic_process_automation21.0.0cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.7.1cpe:2.3:a:ibm:robotic_process_automation:21.0.7.1:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

24.0%

Related for 386277663F598A3E1F69BD1883C92203ED54D4738A64A8D513983D9EB7D62F8B