First published: Mon Jan 09 2023(Updated: )
IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244075.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Robotic Process Automation | <21.0.5 | |
IBM Robotic Process Automation as a Service | <21.0.5 | |
IBM Robotic Process Automation for Cloud Pak | <21.0.5 | |
Microsoft Windows | ||
Redhat Openshift | ||
<=21.0.0 - 21.0.7.1, 23.0.0 - 23.0.1 | ||
<=21.0.0 - 21.0.7.1, 23.0.0 - 23.0.1 | ||
<=< 23.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22594 is medium (5.4).
CVE-2023-22594 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Versions 20.12.0 through 21.0.4 of IBM Robotic Process Automation for Cloud Pak are affected by CVE-2023-22594.
Apply the necessary security patch or update to a version that is not vulnerable.
You can find more information about CVE-2023-22594 on the IBM X-Force Exchange website or the IBM support page.