Description

A recently identified security flaw in IBM Robotic Process Automation (RPA), known as CVE-2024-51456, has raised significant concerns regarding the potential for data breaches. This vulnerability enables remote attackers to take advantage of weaknesses in cryptographic implementations, potentially gaining access to sensitive data. IBM has released a security bulletin that outlines the nature of the issue and offers guidance on steps to mitigate the risk. The root cause of the vulnerability is the insecure use of the RSA algorithm without Optimal Asymmetric Encryption Padding (OAEP), classified under CWE-780 (Use of RSA Algorithm without OAEP). This weakness allows attackers to carry out a crypto-analytic attack that could lead to the interception or retrieval of sensitive data processed by the affected systems. The flaw primarily threatens data confidentiality, but it does not affect system integrity or availability. The CVE-2024-51456 vulnerability has a CVSS Base Score of 5.9, which indicates a moderate severity level. The attack vector is classified as network-based, requiring a high level of attack complexity, with no need for user privileges or interaction. The main impact is on the confidentiality of data, rated as high, while the system’s integrity and availability remain unaffected. IBM has acknowledged the issue and has taken steps to release updated software versions to address the problem. For users running affected versions of IBM Robotic Process Automation (21.0.0 to 21.0.7.19 and 23.0.0 to 23.0.19), it is highly recommended to upgrade to version 23.0.20 or higher. IBM has provided detailed instructions on how to implement the necessary fixes. For those using older versions, specifically 21.0.0 to 21.0.7.19, IBM has offered mitigation steps as a temporary solution until a full upgrade can be performed. Taking action promptly is essential to protect sensitive information and maintain the security of automation processes.