CVE-2022-41740

Severity
4.6MEDIUM
EPSS
0.0%
top 86.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5

Description

IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/robotic_process_automation20.1221.0.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pfcx-mq53-xrff: IBM Robotic Process Automation 202023-01-05
CVEList
IBM Robotic Process Automation information disclosure2023-01-05
CVE-2022-41740 (MEDIUM CVSS 4.6) | IBM Robotic Process Automation 20.1 | cvebase.io