Lucene search

K
ibmIBM56E1491E4014B5ABABB247E40749BCB8FE92B1BA06B867CE4E14C083CD1B2365
HistoryJan 17, 2023 - 4:33 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to man in the middle attacks

2023-01-1716:33:39
www.ibm.com
16
ibm robotic process automation
man-in-the-middle attacks
vulnerability
http
sensitive information
remediation
cloud pak
version 21.0.3

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

40.2%

Summary

IBM Robotic Process Automation defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques.

Vulnerability Details

CVEID:CVE-2023-22863
**DESCRIPTION:**IBM Robotic Process Automation defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/244109 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation < 21.0.3
IBM Robotic Process Automation for Cloud Pak < 21.0.3
IBM Robotic Process Automation as a Service < 21.0.3

Remediation/Fixes

**IBM strongly recommends addressing the vulnerability now.**Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation < 21.0.3 Download 21.0.3 or higher, and follow instructions.
IBM Robotic Process Automation for Cloud Pak < 21.0.3 Update to 21.0.3 or higher, follow instructions.
IBM Robotic Process Automation as a Service < 21.0.3 No action required as SaaS servers have been udpated to 21.0.3 or later.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch20.12.
OR
ibmrobotic_process_automationMatch21.0.2

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

40.2%

Related for 56E1491E4014B5ABABB247E40749BCB8FE92B1BA06B867CE4E14C083CD1B2365