Lucene search

K
ibmIBMA79F99565B122E6C5CEB08C7A40F34060F62C246F46AF7C6B4FC01148EE84A5C
HistoryApr 01, 2022 - 3:07 p.m.

Security Bulletin: Due to use of PostgreSQL, IBM Robotic Process Automation with Automation Anywhere is vulnerable to data confidentiality (CVE-2021-32029)

2022-04-0115:07:31
www.ibm.com
12

0.001 Low

EPSS

Percentile

43.0%

Summary

There are vulnerabilities in the PostgreSQL used by IBM Robotic Process Automation with Automation Anywhere. This affects the IBM Robotic Process Automation with Automation Anywhere control room application.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation with Automation Anywhere 11.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by switching to Microsoft SQL Server or upgrading to IBM Robotic Process Automation with Automation Anywhere 19.0.

CVEID:CVE-2021-32029
**DESCRIPTION:**A flaw was found in PostgreSQL. Using an UPDATE … RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
CVSS Base score: 6.5
CVSS Temporal Score: See: <https://exchange.xforce.ibmcloud.com/vulnerabilities/207909&gt; for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

Workarounds and Mitigations

None