CVE Published: 15/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: ibm |
Vendor: IBM |
Product: Robotic Process Automation Status : PUBLISHED
CVE-2023-22591 Description
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
Metrics
CVSS Version: 3.1 |
Base Score: 3.9 LOW Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L