First published: Fri May 06 2022(Updated: )
IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.2.4 | |
Microsoft Windows | ||
IBM Robotic Process Automation | <=< 21.0.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22414.
The severity level of CVE-2022-22414 is medium with a value of 5.5.
A local user can exploit CVE-2022-22414 to obtain sensitive web service configuration credentials from system memory.
Versions of IBM Robotic Process Automation below 21.0.2.4 are affected by CVE-2022-22414.
To fix CVE-2022-22414, apply the patch provided by IBM Robotic Process Automation 21.0.2-IBMRPA-IF004.