CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
74.9%
There is a vulnerability in Microsoft Azure Identity SDK used by IBM Robotic Process Automation as part of API configuration. An attacker could exploit this vulnerability to execute arbitrary code on the system, caused by an integer overflow. (CVE-2020-36414).
CVEID:CVE-2023-36414
**DESCRIPTION:**Microsoft Azure Identity SDK could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an integer overflow. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268016 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Robotic Process Automation | 21.0.0 - 21.0.7.11, 23.0.0 - 23.0.11 |
IBM Robotic Process Automation for Cloud Pak | 21.0.0 - 21.0.7.11, 23.0.0 - 23.0.11 |
IBM strongly recommends addressing the vulnerability now.
Product(s) | **Version(s) number and/or range ** | Remediation/Fix/Instructions |
---|---|---|
IBM Robotic Process Automation | 21.0.0 - 21.0.7.11 | Download 21.0.7.12 or higher and follow these instructions. |
IBM Robotic Process Automation for Cloud Pak | 21.0.0 - 21.0.7.11 | Update to 21.0.7.12 or higher using the following instructions. |
IBM Robotic Process Automation | 23.0.0 - 23.0.11 | Download 23.0.12 or higher and follow these instructions. |
IBM Robotic Process Automation for Cloud Pak
| 23.0.0 - 23.0.11| Update to 23.0.12 or higher using the following instructions.
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | robotic_process_automation | 21.0.0 | cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:* |
ibm | robotic_process_automation | 21.0.7.11 | cpe:2.3:a:ibm:robotic_process_automation:21.0.7.11:*:*:*:*:*:*:* |
ibm | robotic_process_automation | 23.0.0 | cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:* |
ibm | robotic_process_automation | 23.0.11 | cpe:2.3:a:ibm:robotic_process_automation:23.0.11:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
74.9%