IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Robotic_process_automation | Ibm | 21.0.0 (including) | 21.0.7.1 (including) |
| Robotic_process_automation | Ibm | 23.0.0 (including) | 23.0.0 (including) |
| Robotic_process_automation | Ibm | 23.0.1 (including) | 23.0.1 (including) |