Lucene search

K
ibmIBM90669E3E6B432563789D379CEC0FB493DA582D40CFDBCFFB48E76991B745B136
HistoryApr 13, 2020 - 10:58 p.m.

Security Bulletin: PostgreSQL vulnerabilities in IBM Robotic Process Automation with Automation Anywhere (CVE-2019-10164)

2020-04-1322:58:26
www.ibm.com
11

0.729 High

EPSS

Percentile

98.1%

Summary

IBM Robotic Process Automation with Automation Anywhere is vulnerable to attacks involving PostgreSQL.

Vulnerability Details

CVEID:CVE-2019-10164
**DESCRIPTION:**PostgreSQL is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. By setting a specially-crafted password, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/167576 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation with Automation Anywhere 11.0

Remediation/Fixes

Product VRMF Remediation / First Fix
IBM Robotic Process Automation with Automation Anywhere 11.0.0.8 IBM Robotic Process Automation Anywhere v11.0.0.8 Date 1/21/2020

Workarounds and Mitigations

None