CVE-2024-49825
14.04.2025, 15:15
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | robotic_process_automation | 21.0.0 ≤ 𝑥 ≤ 21.0.7.20 |
ibm | robotic_process_automation | 23.0.0 ≤ 𝑥 ≤ 23.0.20 |
ibm | robotic_process_automation_for_cloud_pak | 21.0.0 ≤ 𝑥 ≤ 21.0.7.20 |
ibm | robotic_process_automation_for_cloud_pak | 23.0.0 ≤ 𝑥 ≤ 23.0.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration