First published: Thu May 12 2022(Updated: )
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | >=21.0.1<21.0.1.7 | |
IBM Robotic Process Automation | >=21.0.2<21.0.2.5 | |
IBM Robotic Process Automation | =21.0.0 | |
IBM Robotic Process Automation as a Service | <=All | |
IBM Robotic Process Automation | <=< 21.0.2.5 | |
IBM Robotic Process Automation | <=< 21.0.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22334 is considered a high severity vulnerability due to unauthorized access to sensitive tenant information.
To remediate CVE-2022-22334, upgrade IBM Robotic Process Automation to versions higher than 21.0.1.7 or 21.0.2.5.
CVE-2022-22334 affects IBM Robotic Process Automation versions 21.0.0, 21.0.1, and 21.0.2.
Exploitation of CVE-2022-22334 allows unauthorized users to gain access to information from protected tenants.
Yes, CVE-2022-22334 can affect IBM Robotic Process Automation as a Service, especially if using vulnerable versions.