Inclusion of Sensitive Information in Log Files in IBM Robotic Process Automation - CVE-2023-38732
Published: October 4, 2023
Vulnerability identifier: #VU81478
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38732
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files. A remote user can read the log files and gain access to sensitive data.
Affected software
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2023-38732
Install updates from vendor's website.
IBM Robotic Process Automation - update to 21.0.7.1
Robotic Process Automation for Cloud Pak - update to 21.0.7.1
Robotic Process Automation for Cloud Pak - update to 21.0.7.1