CVE-2023-45189

Severity
6.5MEDIUM
EPSS
0.1%
top 79.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateNov 4

Description

A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5ibm/robotic_process_automation_for_cloud_pak21.0.021.0.7.10+1
CVEListV5ibm/robotic_process_automation21.0.021.0.7.10+1
NVDibm/robotic_process_automation21.0.021.0.7+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6wgw-qc2r-6vj3: A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 212023-11-04
CVEList
IBM Robotic Process Automation information disclosure2023-11-03
CVE-2023-45189 (MEDIUM CVSS 6.5) | A vulnerability in IBM Robotic Proc | cvebase.io