#VU73190 Insufficiently protected credentials in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2023-25680

 

#VU73190 Insufficiently protected credentials in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2023-25680

Published: March 9, 2023


Vulnerability identifier: #VU73190
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-25680
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
Software vendor:
IBM Corporation

Description

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to credentials are not obfuscated while editing queue provider details. An attacker with physical access to the system can obtain credentials of application users.


Remediation

Install updates from vendor's website.

External links