Vulnerability Name: | CVE-2023-22591 (CCN-243710) | ||||||||||||
Assigned: | 2023-03-08 | ||||||||||||
Published: | 2023-03-08 | ||||||||||||
Updated: | 2023-03-19 | ||||||||||||
Summary: | |||||||||||||
CVSS v3 Severity: | 3.9 Low (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) 3.4 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
3.4 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.7 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-22591 Source: XF Type: UNKNOWN ibm-rpa-cve-202322591-session-fixation(243710) Source: CCN Type: IBM Security Bulletin 6962175 (Robotic Process Automation) IBM Robotic Process Automation is vulnerable to session tokens not being invalidated after password reset. | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
BACK |