First published: Thu Dec 22 2022(Updated: )
IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.7 | |
IBM Robotic Process Automation as a Service | <21.0.7 | |
IBM Robotic Process Automation for Cloud Pak | <21.0.7 | |
Redhat Openshift | ||
Microsoft Windows | ||
IBM Robotic Process Automation for Cloud Pak | <=< 21.0.7 | |
IBM Robotic Process Automation | <=< 21.0.7 | |
IBM Robotic Process Automation as a Service | <=< 21.0.7 | |
All of | ||
Any of | ||
IBM Robotic Process Automation | <21.0.7 | |
IBM Robotic Process Automation as a Service | <21.0.7 | |
IBM Robotic Process Automation for Cloud Pak | <21.0.7 | |
Any of | ||
Redhat Openshift | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43573 is a vulnerability in IBM Robotic Process Automation that allows for the exposure of the name and email of the creator/modifier of platform level objects.
CVE-2022-43573 affects IBM Robotic Process Automation versions 20.12 through 21.0.6, as well as IBM Robotic Process Automation as a Service and IBM Robotic Process Automation for Cloud Pak versions up to and excluding 21.0.7.
CVE-2022-43573 has a severity rating of 5.3, which is considered medium.
To fix CVE-2022-43573, update to IBM Robotic Process Automation version 21.0.7 or newer, and apply the necessary patches for IBM Robotic Process Automation as a Service and IBM Robotic Process Automation for Cloud Pak versions.
You can find more information about CVE-2022-43573 at the IBM X-Force ID: 238678 page and the IBM support page.