PT-2022-23203 · Blue Prism · Blue Prism Enterprise

CVE-2022-36115

·

Published

2022-08-25

·

Updated

2023-08-08

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blue Prism Enterprise versions 6.0 through 7.01
Description The issue allows an authenticated user to reverse engineer the software and circumvent access controls in a misconfigured environment where the Blue Prism Application server is exposed. This can be achieved by abusing the CreateProcessAutosave() method to inject malicious functionality into a development process. If a user recovers unsaved work using the last saved version after a warning, the malicious code could enter the workflow. This code could then be run in a production environment if the process action stages are not fully reviewed before publishing.
Recommendations For Blue Prism Enterprise versions 6.0 through 7.01, as a temporary workaround, consider restricting access to the CreateProcessAutosave() method until a patch is available. Additionally, ensure that all process action stages are fully reviewed before publishing to prevent potential malicious code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-36115

Affected Products

Blue Prism Enterprise