Security Advisory

CVE-2022-36119

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-08-25 23:00:13
Last updated 2024-08-03 09:52:00
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of insecure deserialization. Exploitation of this vulnerability allows for code to be executed in the context of the Blue Prism Server service.