CVE-2022-22413: SQL Injection
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.
Other sources
IBM Robotic Process Automation is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22413?
CVE-2022-22413 is considered a high-severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2022-22413?
To fix CVE-2022-22413, update IBM Robotic Process Automation to version 21.0.2.4 or later.
Who is affected by CVE-2022-22413?
CVE-2022-22413 affects IBM Robotic Process Automation versions 21.0.0, 21.0.1, and 21.0.2.
Can CVE-2022-22413 be exploited remotely?
Yes, CVE-2022-22413 can be exploited remotely by sending specially crafted SQL statements.
What type of attack can CVE-2022-22413 enable?
CVE-2022-22413 can enable an attacker to view, add, modify, or delete information in the affected database.