Lucene search

K
nvd[email protected]NVD:CVE-2023-23468
HistoryJun 27, 2023 - 7:15 p.m.

CVE-2023-23468

2023-06-2719:15:09
web.nvd.nist.gov
4
ibm
rpa
cloud pak
security vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

9.0%

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500.

Affected configurations

Nvd
Node
redhatopenshiftMatch-
AND
ibmrobotic_process_automationRange21.0.121.0.7.3
OR
ibmrobotic_process_automationRange23.0.023.0.3
VendorProductVersionCPE
redhatopenshift-cpe:2.3:a:redhat:openshift:-:*:*:*:*:*:*:*
ibmrobotic_process_automation*cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-23468