First published: Sat Jun 18 2022(Updated: )
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.3 | |
IBM Robotic Process Automation as a Service | ||
IBM Robotic Process Automation for Cloud Pak | <21.0.3 | |
Microsoft Windows | ||
<=< 21.0.3 | ||
<=< 21.0.3 | ||
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM Robotic Process Automation is CVE-2022-22490.
The severity of CVE-2022-22490 is medium with a severity value of 4.9.
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 are affected by CVE-2022-22490.
A privileged user can obtain sensitive Azure bot credential information in IBM Robotic Process Automation versions prior to 21.0.3.
You can find more information about CVE-2022-22490 in the IBM X-Force ID: 226342 and in the IBM support pages.