CVE-2022-38710: IBM Robotic Process Automation information disclosure
"IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version information that could aid in further attacks against the system. IBM X-Force ID: 234292."
Other sources
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.
— MITRE
IBM Robotic Process Automation could disclose sensitive version information that could aid in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Robotic Process Automation vulnerability?
The vulnerability ID for this IBM Robotic Process Automation vulnerability is CVE-2022-38710.
What is the severity of CVE-2022-38710?
The severity of CVE-2022-38710 is medium with a CVSS score of 5.3.
Which versions of IBM Robotic Process Automation are affected by CVE-2022-38710?
Versions up to and excluding 21.0.3 of IBM Robotic Process Automation, IBM Robotic Process Automation as a Service, and IBM Robotic Process Automation for Cloud Pak are affected by CVE-2022-38710.
How can I fix CVE-2022-38710?
To fix CVE-2022-38710, apply the patch provided by IBM for Robotic Process Automation version 21.0.3 or upgrade to a version higher than 21.0.3.
Where can I find more information about CVE-2022-38710?
You can find more information about CVE-2022-38710 on the IBM Support Pages (https://www.ibm.com/support/pages/node/6831681) and IBM X-Force Exchange (https://exchange.xforce.ibmcloud.com/vulnerabilities/234292).