Lucene search

K
ibmIBM9B2C4E633D82212CFEEFB336A26813D5228AA2011CD0D31200A76AD1DA4100BA
HistoryJul 29, 2022 - 3:57 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to privilege escalation (CVE-2022-30616)

2022-07-2915:57:14
www.ibm.com
26
ibm robotic process automation
privilege escalation
vulnerability
update
cloud pak
service

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.9%

Summary

Security Bulletin: IBM Robotic Process Automation is vulnerable to privilege escalation (CVE-2022-30616)

Vulnerability Details

CVEID:CVE-2022-30616
**DESCRIPTION:**IBM Robotic Process Automation could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs.
CVSS Base score: 8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/227978 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation for Cloud Pak < 21.0.3
IBM Robotic Process Automation as a Service < 21.0.3
IBM Robotic Process Automation < 21.0.3

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) Version(s) Remediation/Fix/Instructions
IBM Robotic Process Automation < 21.0.3 Update to 21.0.3 or higher
IBM Robotic Process Automation for Cloud Pak < 21.0.3 Update to 21.0.3 or higher
IBM Robotic Process Automation as a Service < 21.0.3 No action required as IBM Robotic Process Automation as a Service servers have been updated to 21.0.3 or higher.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.1
OR
ibmrobotic_process_automationMatch21.0.2
VendorProductVersionCPE
ibmrobotic_process_automation21.0.0cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.1cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.2cpe:2.3:a:ibm:robotic_process_automation:21.0.2:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.9%

Related for 9B2C4E633D82212CFEEFB336A26813D5228AA2011CD0D31200A76AD1DA4100BA