CVE-2022-33954: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.
Other sources
IBM Robotic Process Automation could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33954?
The severity of CVE-2022-33954 is rated as high, due to the potential for sensitive information disclosure.
How do I fix CVE-2022-33954?
To mitigate CVE-2022-33954, update IBM Robotic Process Automation to version 21.0.3 or later to ensure credentials are properly protected.
What versions of IBM Robotic Process Automation are affected by CVE-2022-33954?
CVE-2022-33954 affects IBM Robotic Process Automation versions 21.0.1, 21.0.2, and earlier than 21.0.3.
Who is impacted by CVE-2022-33954?
Users with physical access to the system running affected versions of IBM Robotic Process Automation may be impacted by CVE-2022-33954.
What type of information can be exposed by CVE-2022-33954?
CVE-2022-33954 can potentially expose sensitive credentials due to insufficient protection.