CVE-2022-38710
03.11.2022, 20:15
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | robotic_process_automation | 𝑥 < 21.0.3 |
ibm | robotic_process_automation_as_a_service | 𝑥 < 21.0.3 |
ibm | robotic_process_automation_for_cloud_pak | 𝑥 < 21.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control SphereThe application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.