CVE-2023-23468IBM Robotic Process Automation FOR Cloud PAK vulnerability

3 documents3 sources
Severity
5.5MEDIUMNVD
CNA5.1
EPSS
0.0%
top 94.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27

Description

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/robotic_process_automation_for_cloud_pak21.0.121.0.7.3+1
NVDibm/robotic_process_automation21.0.121.0.7.3+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f9wj-wv6x-9pj8: IBM Robotic Process Automation for Cloud Pak 212023-06-27
CVEList
IBM Robotic Process Automation for Cloud Pak access control2023-06-27
CVE-2023-23468 — IBM vulnerability | cvebase