First published: Mon Jun 27 2022(Updated: )
IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 227125.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.1 | |
IBM Robotic Process Automation as a Service | <21.0.1 | |
<=< 21.0.1 | ||
<=< 21.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22503.
The severity of CVE-2022-22503 is medium, with a severity value of 6.1.
CVE-2022-22503 could allow a remote attacker to hijack the clicking action of the victim, potentially leading to further attacks against the system.
IBM Robotic Process Automation versions up to and excluding 21.0.1 are affected by CVE-2022-22503.
To fix CVE-2022-22503, it is recommended to apply the patch provided by IBM. You can download the patch from the following URL: [https://www.ibm.com/support/pages/download-ibm-robotic-process-automation-2101](https://www.ibm.com/support/pages/download-ibm-robotic-process-automation-2101)