Insufficiently protected credentials in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2023-25680

 

Insufficiently protected credentials in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2023-25680

Published: March 9, 2023


Vulnerability identifier: #VU73190
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25680
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to credentials are not obfuscated while editing queue provider details. An attacker with physical access to the system can obtain credentials of application users.


Affected software

IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2023-25680

Install updates from vendor's website.

IBM Robotic Process Automation - update to 21.0.6
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins