CVE-2023-25680

IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:09

Type Values Removed Values Added
Summary IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032. IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.

19 Mar 2023, 03:55

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:robotic_process_automation_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-200 NVD-CWE-noinfo
References (MISC) https://www.ibm.com/support/pages/node/6962207 - (MISC) https://www.ibm.com/support/pages/node/6962207 - Patch, Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/247032 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/247032 - VDB Entry, Vendor Advisory
First Time Ibm
Ibm robotic Process Automation For Cloud Pak
Ibm robotic Process Automation
Ibm robotic Process Automation As A Service

15 Mar 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-15 20:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-25680

Mitre link : CVE-2023-25680

CVE.ORG link : CVE-2023-25680


JSON object : View

Products Affected

ibm

  • robotic_process_automation_as_a_service
  • robotic_process_automation
  • robotic_process_automation_for_cloud_pak
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor