CVE-2022-22506: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.
Other sources
IBM Robotic Process Automation contains a vulnerability that could allow user ids may be exposed across tenants.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22506?
The severity of CVE-2022-22506 is classified as high due to the potential exposure of user IDs across tenants.
How do I fix CVE-2022-22506?
To fix CVE-2022-22506, apply the relevant patches provided by IBM for Robotic Process Automation version 21.0.2.
What products are affected by CVE-2022-22506?
CVE-2022-22506 affects IBM Robotic Process Automation, Robotic Process Automation for Cloud Pak, and Robotic Process Automation as a Service, all up to version 21.0.2.
What could happen if CVE-2022-22506 is exploited?
If CVE-2022-22506 is exploited, user IDs may be exposed, leading to potential unauthorized access across tenants.
Is there a workaround for CVE-2022-22506?
Currently, applying the official patches from IBM is the recommended solution for CVE-2022-22506 as there are no known workarounds.