CVE-2022-43574: High severity IBM Robotic Process Automation vulnerability
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."
Other sources
IBM Robotic Process Automation is vulnerable to incorrect permission assignment which could allow access to application configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
IBM Robotic Process Automation (21.0.1, 21.0.2, 21.0.3, 21.0.4, 21.0.5): review and correct file/application configuration permissions to prevent unauthorized access to application configurations (IBM X-Force ID: 238679).
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Robotic Process Automation vulnerability?
The vulnerability ID for this IBM Robotic Process Automation vulnerability is CVE-2022-43574.
What is the severity rating of CVE-2022-43574?
The severity rating of CVE-2022-43574 is high, with a CVSS score of 7.5.
Which versions of IBM Robotic Process Automation are affected by CVE-2022-43574?
IBM Robotic Process Automation versions 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 are affected by CVE-2022-43574.
How can I fix the CVE-2022-43574 vulnerability?
To fix the CVE-2022-43574 vulnerability, you need to update your IBM Robotic Process Automation to version 21.0.6 or higher.
Where can I find more information about CVE-2022-43574 vulnerability?
You can find more information about the CVE-2022-43574 vulnerability on the IBM support page (https://www.ibm.com/support/pages/node/6831645) and the IBM X-Force Exchange (https://exchange.xforce.ibmcloud.com/vulnerabilities/238679).