CVE-2022-22434: Medium severity ibm robotic process automation for services vulnerability
Published Apr 13, 2022
·Updated
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159.
Other sources
IBM Robotic Process Automation could allow a user with physical access to create an API request modified to create additional objects.
Affected Software
7 affected components
IBM Robotic Process Automation<=21.0.2
IBM Robotic Process Automation<=21.0.1
IBM Robotic Process Automation as a Service<=All
IBM Robotic Process Automation=21.0.1
IBM Robotic Process Automation=21.0.2
IBM Robotic Process Automation as a Service
Microsoft Windows
Remediation
Patch Available
Event History
Apr 13, 2022
CVE Published
via IBM·12:00 AM
May 5, 2022
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22434?
The severity of CVE-2022-22434 is rated as medium with a CVSS score of 4.6.
2
How can the vulnerability CVE-2022-22434 be exploited?
The vulnerability in IBM Robotic Process Automation could be exploited by a user with physical access to create an API request modified to create additional objects.