First published: Tue Dec 20 2022(Updated: )
IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation for Cloud Pak | <=< 21.0.7 | |
IBM Robotic Process Automation | <=< 21.0.7 | |
IBM Robotic Process Automation | <21.0.7 | |
IBM Robotic Process Automation for Cloud Pak | <21.0.7 | |
Redhat Openshift | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-41740 is medium, with a CVSS score of 4.6.
An attacker with physical access to the system can exploit CVE-2022-41740 to obtain highly sensitive information from system memory.
IBM Robotic Process Automation versions up to 21.0.6 are affected by CVE-2022-41740.
Yes, IBM Robotic Process Automation for Cloud Pak versions up to 21.0.6 are vulnerable to CVE-2022-41740.
To fix CVE-2022-41740, update to IBM Robotic Process Automation version 21.0.7 or higher.