CVE-2022-22414: Medium severity ibm robotic process automation for services vulnerability
Published May 6, 2022
·Updated
IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.
Other sources
IBM Robotic Process Automation could allow a local user to obtain sensitive web service configuration credentials from system memory.
Affected Software
3 affected componentsFixes available
IBM Robotic Process Automation<=< 21.0.2.4
IBM Robotic Process Automation<21.0.2.4
Microsoft Windows
Remediation
Patch Available
Event History
May 6, 2022
CVE Published
via IBM·12:00 AM
Jun 20, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-22414.
2
What is the severity level of CVE-2022-22414?
The severity level of CVE-2022-22414 is medium with a value of 5.5.
3
How can a local user exploit CVE-2022-22414?
A local user can exploit CVE-2022-22414 to obtain sensitive web service configuration credentials from system memory.
4
Which versions of IBM Robotic Process Automation are affected by CVE-2022-22414?
Versions of IBM Robotic Process Automation below 21.0.2.4 are affected by CVE-2022-22414.
5
How can I fix CVE-2022-22414?
To fix CVE-2022-22414, apply the patch provided by IBM Robotic Process Automation 21.0.2-IBMRPA-IF004.