VYPR
Unrated severityNVD Advisory· Published Aug 25, 2022· Updated Aug 3, 2024

CVE-2022-36120

CVE-2022-36120

Description

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated low-privilege users can abuse the `getChartData` function in Blue Prism Enterprise 6.0–7.01 to execute arbitrary MSSQL stored procedures.

Vulnerability

An issue in Blue Prism Enterprise versions 6.0 through 7.01 allows an authenticated user with low or no privileges to circumvent access controls on the getChartData administrative function. This is exploitable only in a misconfigured environment where the Blue Prism Application server is exposed to the attacker. The vulnerability enables the attacker to alter server settings by abusing the getChartData method, ultimately allowing the Blue Prism server to execute any MSSQL stored procedure by name [2].

Exploitation

The attacker must have a valid low-privilege or no-privilege Blue Prism user account and network access to the exposed Application server. The attacker first reverse engineers the Blue Prism software to understand the getChartData function's behavior. Then, by abusing this function, the attacker modifies server settings to enable execution of arbitrary MSSQL stored procedures. The exploitation requires several complex pre-requisites, including a misconfigured environment that exposes the Application server [2].

Impact

Successful exploitation allows the attacker to execute any MSSQL stored procedure by name, potentially leading to unauthorized data access, data manipulation, privilege escalation, or further compromise of the database server. The attacker gains the ability to perform administrative database operations despite having only a low-privilege Blue Prism account.

Mitigation

SS&C Blue Prism has released patches for versions starting at 6.4, and the fix is incorporated in the latest release, version 7.1. Cloud customers are not affected as the Blue Prism Cloud platform follows security best practices. For on-premises deployments, implementing the Blue Prism Robotic Operating Model (ROM) practices—such as logically securing the network, limiting access to approved devices, and allow-listing connections—reduces the likelihood of exploitation [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.