CVE-2023-35900

Severity
5.3MEDIUM
EPSS
0.1%
top 75.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19

Description

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 259368.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5ibm/robotic_process_automation21.0.021.0.7.4+1
NVDibm/robotic_process_automation23.0.023.0.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c5rc-w46c-83hh: IBM Robotic Process Automation for Cloud Pak 212023-07-19
CVEList
IBM Robotic Process Automation information disclosure2023-07-19
CVE-2023-35900 (MEDIUM CVSS 5.3) | IBM Robotic Process Automation for | cvebase.io