CVE-2022-36119
25.08.2022, 23:15
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of insecure deserialization. Exploitation of this vulnerability allows for code to be executed in the context of the Blue Prism Server service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ssctech | blue_prism | 6.4 ≤ 𝑥 < 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References