Improper access control in Aria Automation (formerly vRealize Automation) - CVE-2023-34063

 

Improper access control in Aria Automation (formerly vRealize Automation) - CVE-2023-34063

Published: January 16, 2024 / Updated: September 4, 2024


Vulnerability identifier: #VU85425
CSH Severity: High
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34063
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to remote organizations and workflows.


Affected software

Aria Automation (formerly vRealize Automation)
vRealize Data Protection Extension

How to mitigate CVE-2023-34063

Install updates from vendor's website.

Aria Automation (formerly vRealize Automation) - update to 8.16.0
vRealize Data Protection Extension - addressed in versions 8.11.2.30127, 8.12.2.31368, 8.13.1.32385

External References

Related Security Bulletins