Lucene search

K
ibmIBM920D61834AFF379A2D07C68E51CAFBF19413ABD93132E0044401928F31089F3B
HistoryAug 01, 2023 - 3:07 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes (CVE-2023-23476)

2023-08-0115:07:47
www.ibm.com
24
ibm
robotic process automation
vulnerability
unauthorized access
insufficient authorization validation
api routes
cve-2023-23476
data
ibm cloud pak
mitigation
custom roles
remediation
fix

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

26.1%

Summary

IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes (CVE-2023-23476)

Vulnerability Details

CVEID:CVE-2023-23476
**DESCRIPTION:**IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/245425 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation 21.0.0-21.0.7.latest
IBM Robotic Process Automation for Cloud Pak 21.0.0-21.0.7.latest

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation 21.0.0 - 21.0.7.latest See mitigation instructions
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.latest See mitigation instructions.
IBM Robotic Process Automation >= 23.0.0 Not affected
IBM Robotic Process Automation for Cloud Pak >= 23.0.0 Not affected

Workarounds and Mitigations

To mitigate this issue:

1. Ensure there are no custom roles that include [UsersManage | UsersView ] without the TeamsManage privilege.

2. Ensure there are no custom roles that include [CountersManage | CountersUse | CountersView ] without [ProjectsManage, ProjectsView, ProjectsCreate].

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.7.
VendorProductVersionCPE
ibmrobotic_process_automation21.0.0cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.7.cpe:2.3:a:ibm:robotic_process_automation:21.0.7.:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

26.1%

Related for 920D61834AFF379A2D07C68E51CAFBF19413ABD93132E0044401928F31089F3B