QID 375722
Date Published: 2021-07-26
QID 375722: Blue Prism Robotic Process Automation (RPA) Privilege Escalation Vulnerability
Blue Prism is an RPA platform that enables companies to manage and deploy their digital workforce composed of software robots.
Affected Versions:
Blue Prism Robotic Process Automation Prior to 6.5.0.12573
QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of Blue Prism Robotic Process Automation on Windows.
A vulnerability in the access control of the software can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information.
The attack requires a valid user account to connect to the Blue Prism server, but the roles associated to the account are not required to have any permissions.
Solution
The manufacturer fixed the vulnerability in version 6.5.0.12573
Vendor References
CVEs related to QID 375722
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SYSS-2019-002 |
|