CVE-2022-41740: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.
Other sources
IBM Robotic Process Automation could allow an attacker with physical access to the system to obtain highly sensitive information from system memory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41740?
The severity of CVE-2022-41740 is medium, with a CVSS score of 4.6.
How can an attacker exploit CVE-2022-41740?
An attacker with physical access to the system can exploit CVE-2022-41740 to obtain highly sensitive information from system memory.
Which versions of IBM Robotic Process Automation are affected by CVE-2022-41740?
IBM Robotic Process Automation versions up to 21.0.6 are affected by CVE-2022-41740.
Is IBM Robotic Process Automation for Cloud Pak vulnerable to CVE-2022-41740?
Yes, IBM Robotic Process Automation for Cloud Pak versions up to 21.0.6 are vulnerable to CVE-2022-41740.
How can I fix CVE-2022-41740?
To fix CVE-2022-41740, update to IBM Robotic Process Automation version 21.0.7 or higher.