CVE-2022-43573Sensitive Information Exposure in IBM Robotic Process Automation

Severity
5.3MEDIUMNVD
CNA3.1
EPSS
0.2%
top 62.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5

Description

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gf2w-gwrg-m3gv: IBM Robotic Process Automation 202023-01-05
CVEList
IBM Robotic Process Automation information disclosure2023-01-05
CVE-2022-43573 — Sensitive Information Exposure in IBM | cvebase