Lucene search

K
ibmIBMA9B8CE1816FD66796A060C321AF9253EB5E14FEE80E72B760069A2351B422420
HistoryMar 08, 2023 - 2:17 p.m.

Security Bulletin: A vulnerability in IBM Robotic Process Automation may allow a user to create invalid credential pools (CVE-2022-46773)

2023-03-0814:17:40
www.ibm.com
12
ibm robotic process automation
vulnerability
invalid credential pools
security fix
update
ibm cloud pak
ibm as a service

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

18.0%

Summary

There is a vulnerability in IBM Robotic Process Automation which may allow an authenticated user to create invalid credential pools. (CVE-2022-46773). This bulletin identifies the security fixes to apply to address this vulnerability.

Vulnerability Details

CVEID:CVE-2022-46773
**DESCRIPTION:**IBM Robotic Process automation is vulnerable to client side validation bypass for credential pools. Invalid credential pools may be created as a result.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/242951 for the current score.
CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation 21.0.0 - 21.0.7, 23.0.0
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7, 23.0.0
IBM Robotic Process Automation as a Service < 23.0.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation < 21.0.7.1 Download 21.0.7.1 or higher, and follow instructions.
IBM Robotic Process Automation 23.0.0 Download 23.0.1 or higher and follow instructions.
IBM Robotic Process Automation for Cloud Pak < 21.0.7.1 Update to 21.0.7.2 or higher using the following instructions.
IBM Robotic Process Automation for Cloud Pak 23.0.0 Update to 23.0.2 or higher using the following instructions.
IBM Robotic Process Automation as a Service < 23.0.1 No action is necessary as all IBM Robotic Process Automation as a Service servers have been updated to 23.0.2 or higher.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.7
OR
ibmrobotic_process_automationMatch23.0.0

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

18.0%

Related for A9B8CE1816FD66796A060C321AF9253EB5E14FEE80E72B760069A2351B422420