First published: Wed Jun 22 2022(Updated: )
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation for Services | <=< 21.0.3 | |
IBM Robotic Process Automation for Cloud Pak | <=< 21.0.3 | |
IBM Robotic Process Automation as a Service | <=< 21.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33954 is rated as high, due to the potential for sensitive information disclosure.
To mitigate CVE-2022-33954, update IBM Robotic Process Automation to version 21.0.3 or later to ensure credentials are properly protected.
CVE-2022-33954 affects IBM Robotic Process Automation versions 21.0.1, 21.0.2, and earlier than 21.0.3.
Users with physical access to the system running affected versions of IBM Robotic Process Automation may be impacted by CVE-2022-33954.
CVE-2022-33954 can potentially expose sensitive credentials due to insufficient protection.