Security Bulletin: IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes (CVE-2023-23476)
Discription

## Summary

IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes (CVE-2023-23476)

## Vulnerability Details

** CVEID: **[CVE-2023-23476]()
** DESCRIPTION: **IBM Robotic Process Automation is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes.
CVSS Base score: 3.1
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/245425]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)

## Affected Products and Versions

Affected Product(s)| Version(s)
—|—
IBM Robotic Process Automation| 21.0.0-21.0.7.latest
IBM Robotic Process Automation for Cloud Pak| 21.0.0-21.0.7.latest

## Remediation/Fixes

**IBM strongly recommends addressing the vulnerability now.**

**Product(s)**| **Version(s) number and/or range **| **Remediation/Fix/Instructions**
—|—|—
IBM Robotic Process Automation| 21.0.0 – 21.0.7.latest| See mitigation instructions
IBM Robotic Process Automation for Cloud Pak| 21.0.0 – 21.0.7.latest| See mitigation instructions.
IBM Robotic Process Automation| >= 23.0.0| Not affected
IBM Robotic Process Automation for Cloud Pak| >= 23.0.0| Not affected

## Workarounds and Mitigations

To mitigate this issue:

1. Ensure there are no custom roles that include [UsersManage | UsersView ] without the TeamsManage privilege.

2. Ensure there are no custom roles that include [CountersManage | CountersUse | CountersView ] without [ProjectsManage, ProjectsView, ProjectsCreate].

##Read More

Back to Main

Subscribe for the latest news: