PT-2022-23203 · Blue Prism · Blue Prism Enterprise
CVE-2022-36115
·
Published
2022-08-25
·
Updated
2023-08-08
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blue Prism Enterprise versions 6.0 through 7.01
Description
The issue allows an authenticated user to reverse engineer the software and circumvent access controls in a misconfigured environment where the Blue Prism Application server is exposed. This can be achieved by abusing the
CreateProcessAutosave() method to inject malicious functionality into a development process. If a user recovers unsaved work using the last saved version after a warning, the malicious code could enter the workflow. This code could then be run in a production environment if the process action stages are not fully reviewed before publishing.Recommendations
For Blue Prism Enterprise versions 6.0 through 7.01, as a temporary workaround, consider restricting access to the
CreateProcessAutosave() method until a patch is available. Additionally, ensure that all process action stages are fully reviewed before publishing to prevent potential malicious code execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blue Prism Enterprise