First published: Wed Jun 22 2022(Updated: )
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.2.5 | |
IBM Robotic Process Automation as a Service | <21.0.2.5 | |
IBM Robotic Process Automation for Cloud Pak | <21.0.2.5 | |
<=< 21.0.2.5 | ||
<=< 21.0.2.5 | ||
<=< 21.0.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33953 is medium, with a severity value of 4.6.
A user with physical access to the system can exploit CVE-2022-33953 to obtain sensitive information.
IBM Robotic Process Automation versions up to and including 21.0.2.5 are affected by CVE-2022-33953.
You can fix CVE-2022-33953 by applying the patch provided by IBM for the affected software versions.
You can find more information about CVE-2022-33953 on the IBM X-Force ID page and the IBM support page.