CVE-2022-36774: Medium severity IBM Robotic Process Automation vulnerability
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.
Other sources
IBM Robotic Process automation is vulnerable to man in the middle attacks through manipulation of the client proxy configuration.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-36774?
CVE-2022-36774 is a vulnerability in IBM Robotic Process Automation that allows for man-in-the-middle attacks through manipulation of the client proxy configuration.
Which versions of IBM Robotic Process Automation are affected by CVE-2022-36774?
IBM Robotic Process Automation versions 21.0.0, 21.0.1, and 21.0.2 are affected by CVE-2022-36774.
How can CVE-2022-36774 be exploited?
CVE-2022-36774 can be exploited by manipulating the client proxy configuration to perform man-in-the-middle attacks.
What is the severity of CVE-2022-36774?
CVE-2022-36774 has a severity level of medium (6.5).
How can I fix CVE-2022-36774?
To fix CVE-2022-36774, update IBM Robotic Process Automation to version 21.0.3 or higher.