CVE-2022-43573: IBM Robotic Process Automation information disclosure
IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678.
Other sources
IBM Robotic Process Automation is vulnerable to exposure of the name and email for the creator/modifier of platform level objects.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43573?
CVE-2022-43573 is a vulnerability in IBM Robotic Process Automation that allows for the exposure of the name and email of the creator/modifier of platform level objects.
How does CVE-2022-43573 affect IBM Robotic Process Automation?
CVE-2022-43573 affects IBM Robotic Process Automation versions 20.12 through 21.0.6, as well as IBM Robotic Process Automation as a Service and IBM Robotic Process Automation for Cloud Pak versions up to and excluding 21.0.7.
What is the severity of CVE-2022-43573?
CVE-2022-43573 has a severity rating of 5.3, which is considered medium.
How can I fix CVE-2022-43573?
To fix CVE-2022-43573, update to IBM Robotic Process Automation version 21.0.7 or newer, and apply the necessary patches for IBM Robotic Process Automation as a Service and IBM Robotic Process Automation for Cloud Pak versions.
Where can I find more information about CVE-2022-43573?
You can find more information about CVE-2022-43573 at the IBM X-Force ID: 238678 page and the IBM support page.