#VU73190 Insufficiently protected credentials in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2023-25680
Published: March 9, 2023
Vulnerability identifier: #VU73190
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-25680
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
Software vendor:
IBM Corporation
IBM Corporation
Description
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to credentials are not obfuscated while editing queue provider details. An attacker with physical access to the system can obtain credentials of application users.
Remediation
Install updates from vendor's website.