CVE-2022-22502
24.06.2022, 16:15
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124.
Vendor | Product | Version |
---|---|---|
ibm | robotic_process_automation | 21.0.1 ≤ 𝑥 < 21.0.1.5 |
ibm | robotic_process_automation | 21.0.2 ≤ 𝑥 < 21.0.2.2 |
ibm | robotic_process_automation_as_a_service | 𝑥 < 21.0.2.2 |
ibm | robotic_process_automation_for_cloud_pak | 𝑥 < 21.0.2.2 |
𝑥
= Vulnerable software versions