First published: Mon May 30 2022(Updated: )
IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation for Services | =21.0.2 | |
IBM Robotic Process Automation for Services | <=21.0.2 | |
IBM Robotic Process Automation for Cloud Pak | <=21.0.2 | |
IBM Robotic Process Automation as a Service | <=21.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22506 is classified as high due to the potential exposure of user IDs across tenants.
To fix CVE-2022-22506, apply the relevant patches provided by IBM for Robotic Process Automation version 21.0.2.
CVE-2022-22506 affects IBM Robotic Process Automation, Robotic Process Automation for Cloud Pak, and Robotic Process Automation as a Service, all up to version 21.0.2.
If CVE-2022-22506 is exploited, user IDs may be exposed, leading to potential unauthorized access across tenants.
Currently, applying the official patches from IBM is the recommended solution for CVE-2022-22506 as there are no known workarounds.