Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Robotic_process_automation
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 41 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-08-01 | CVE-2022-22334 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391. | Robotic_process_automation | 4.3 | ||
2022-08-01 | CVE-2022-22505 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288. | Robotic_process_automation | 7.5 | ||
2022-08-01 | CVE-2022-30616 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978. | Robotic_process_automation | 7.2 | ||
2022-08-01 | CVE-2022-33169 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888. | Robotic_process_automation | 6.5 | ||
2022-08-01 | CVE-2022-34338 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. | Robotic_process_automation | 6.5 | ||
2022-08-10 | CVE-2022-22490 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | Robotic_process_automation, Robotic_process_automation_as_a_service, Robotic_process_automation_for_cloud_pak | 4.9 | ||
2022-09-29 | CVE-2022-39168 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. | Robotic_process_automation, Robotic_process_automation_for_cloud_pak, Robotic_process_automation_for_services | 7.5 | ||
2022-10-06 | CVE-2022-22503 | IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 227125. | Robotic_process_automation, Robotic_process_automation_as_a_service | 6.1 | ||
2022-10-06 | CVE-2022-36774 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575. | Robotic_process_automation, Robotic_process_automation_as_a_service, Robotic_process_automation_for_cloud_pak | 5.3 | ||
2022-10-06 | CVE-2022-41294 | IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | Robotic_process_automation | 6.5 |