CVE-2023-35900 MEDIUM

CVE-2023-35900: IBM Robotic Process Automation information disclosure

Vendor Ibm
Product Robotic Process Automation
Weakness CWE-200 · Info exposure
Published July 19, 2023
Last update October 21, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 259368.

Key dates

02Disclosure timeline

July 19, 2023 CVE published
October 21, 2024 Record updated