PT-2022-23206 · Blue Prism · Blue Prism Enterprise

CVE-2022-36118

·

Published

2022-08-25

·

Updated

2023-08-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Blue Prism Enterprise versions 6.0 through 7.01
Description The issue allows an authenticated user to reverse engineer the software and circumvent access controls for the SetProcessAttributes administrative function in a misconfigured environment that exposes the Blue Prism Application server. This enables any user to publish, unpublish, or retire processes by changing the status of a process, an action intended only for users with the Edit Process permission.
Recommendations For Blue Prism Enterprise versions 6.0 through 7.01, consider restricting access to the SetProcessAttributes administrative function until a proper configuration or patch is available to prevent unauthorized users from changing process statuses. Additionally, ensure that the Blue Prism Application server is properly configured to prevent exposure and limit the potential for reverse engineering.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-36118

Affected Products

Blue Prism Enterprise