IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Robotic_process_automation | Ibm | 21.0.1 (including) | 21.0.7.1 (excluding) |
Robotic_process_automation | Ibm | 23.0.0 (including) | 23.0.2 (excluding) |
Robotic_process_automation_as_a_service | Ibm | * | 23.0.2 (excluding) |