NA

CVE-2022-36120

Published: 26/08/2022 Updated: 08/08/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An issue exists in Blue Prism Enterprise 6.0 up to and including 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ssctech blue prism enterprise