Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcxw-vmr7-hmxx

Опубликовано: 18 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18

could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18

could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.

EPSS

Процентиль: 44%
0.00213
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-602

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость программного средства автоматизации бизнес-процессов IBM Robotic Process Automation, связанная с некорректной проверкой безопасности на стороне клиента, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 44%
0.00213
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-602