CVE-2023-22863

Severity
5.9MEDIUM
EPSS
0.1%
top 70.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18

Description

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 244109.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2r26-hc5x-pcmw: IBM Robotic Process Automation 202023-01-18
CVEList
IBM Robotic Process Automation information disclosure2023-01-18
CVE-2023-22863 (MEDIUM CVSS 5.9) | IBM Robotic Process Automation 20.1 | cvebase.io