CVE-2023-22592

Severity
7.8HIGH
EPSS
0.1%
top 76.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18

Description

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 1.4 | Impact: 2.5

Affected Packages2 packages

NVDibm/robotic_process_automation21.0.121.0.5

Patches

🔴Vulnerability Details

2
CVEList
IBM Robotic Process Automation for Cloud Pak insufficient permission settings2023-01-18
GHSA
GHSA-f868-pffj-c6gh: IBM Robotic Process Automation for Cloud Pak 212023-01-18