cbcvebase.

Ibm Robotic Process Automation vulnerabilities

49 known vulnerabilities affecting ibm/robotic_process_automation.

Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH6MEDIUM38LOW1

Vulnerabilities

Page 1 of 3
CVE-2022-22413P3CRITICALCVSS 9.8v21.0.0v21.0.1+1 more2022-05-12
CVE-2022-22413 [CRITICAL] CWE-89 CVE-2022-22413: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote a IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.
nvd
CVE-2023-43058P3CRITICALCVSS 9.8v23.0.92023-10-06
CVE-2023-43058 [CRITICAL] CVE-2023-43058: IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership o IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.
nvd
CVE-2023-38734P3CRITICALCVSS 9.8≥ 21.0.0, ≤ 21.0.7.1v23.0.0+2 more2023-08-22
CVE-2023-38734 [CRITICAL] CWE-269 CVE-2023-38734: IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to i IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.
nvd
CVE-2022-35280P3CRITICALCVSS 9.8v21.0.0v21.0.1+1 more2022-08-10
CVE-2022-35280 [CRITICAL] CWE-521 CVE-2022-35280: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have st IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
nvd
CVE-2022-22433P3HIGHCVSS 7.5fixed in 21.0.1.5v21.0.2+1 more2022-05-05
CVE-2022-22433 [HIGH] CWE-20 CVE-2022-22433: IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attac IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attac
nvd
CVE-2022-22505P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.3v21.0.0+2 more2022-08-01
CVE-2022-22505 [HIGH] CVE-2022-22505: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288.
nvd
CVE-2022-39168P3HIGHCVSS 7.5v21.0.3v21.0.42022-09-29
CVE-2022-39168 [HIGH] CWE-522 CVE-2022-39168: IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.
nvd
CVE-2022-43574P3HIGHCVSS 7.5fixed in 21.0.62022-11-03
CVE-2022-43574 [HIGH] CWE-276 CVE-2022-43574: "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrec "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."
nvd
CVE-2023-22593P3HIGHCVSS 7.8≥ 21.0.1, ≤ 21.0.7.3≥ 23.0.0, ≤ 23.0.32023-06-27
CVE-2023-22593 [HIGH] CWE-863 CVE-2023-22593: IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is v IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074.
nvd
CVE-2022-30616P3HIGHCVSS 7.2≥ 21.0.0, < 21.0.3v21.0.0+2 more2022-08-01
CVE-2022-30616 [HIGH] CVE-2022-30616: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate t IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978.
nvd
CVE-2023-45189P3MEDIUMCVSS 6.5≥ 21.0.0, ≤ 21.0.7.10≥ 23.0.0, ≤ 23.0.102023-11-03
CVE-2023-45189 [MEDIUM] CWE-200 CVE-2023-45189: A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 2 A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752
nvd
CVE-2023-23476P3MEDIUMCVSS 6.5≥ 21.0.0, < 23.0.0≥ 21.0.0, ≤ 21.0.7.latest2023-08-02
CVE-2023-23476 [MEDIUM] CWE-863 CVE-2023-23476: IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.
nvd
CVE-2024-49824P3MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.7.19≥ 23.0.0, < 23.0.19+2 more2025-01-18
CVE-2024-49824 [MEDIUM] CWE-602 CVE-2024-49824: IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
nvd
CVE-2022-22415P4MEDIUMCVSS 6.5v21.0.12022-05-05
CVE-2022-22415 [MEDIUM] CVE-2022-22415: A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029.
nvd
CVE-2023-25680P4MEDIUMCVSS 6.5fixed in 21.0.6≥ 21.0.1, < 21.0.52023-03-15
CVE-2023-25680 [MEDIUM] CWE-200 CVE-2023-25680: IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting cred IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
nvd
CVE-2022-33169P4MEDIUMCVSS 6.5≥ 21.0.0, ≤ 21.0.3v21.0.0+2 more2022-08-01
CVE-2022-33169 [MEDIUM] CWE-522 CVE-2022-33169: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888.
nvd
CVE-2022-30607P4MEDIUMCVSS 6.5v20.10.0v20.12.5+3 more2022-06-17
CVE-2022-30607 [MEDIUM] CWE-200 CVE-2022-30607: IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294.
nvd
CVE-2022-34338P4MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.3v21.0.0+2 more2022-08-01
CVE-2022-34338 [MEDIUM] CWE-269 CVE-2022-34338: IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due t IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962.
nvd
CVE-2022-46773P4MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.7.1v23.0.0+1 more2023-03-15
CVE-2022-46773 [MEDIUM] CWE-287 CVE-2022-46773: IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation by IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
nvd
CVE-2022-41294P4MEDIUMCVSS 6.5≥ 21.0.0, ≤ 21.0.4v21.0.0+4 more2022-10-06
CVE-2022-41294 [MEDIUM] CWE-346 CVE-2022-41294: IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross ori IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.
nvd
Ibm Robotic Process Automation vulnerabilities | cvebase