Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68278
HistoryOct 10, 2022 - 12:00 a.m.

IBM Robotic Process Automation Cross-Site Scripting Vulnerability (CNVD-2022-68278)

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
ibm
robotic process automation
cross-site scripting
vulnerability
cloud pak
javascript
web ui
credentials
attack

EPSS

0.001

Percentile

26.9%

IBM Robotic Process Automation is a robotic process automation product from International Business Machines (IBM), Inc. A cross-site scripting vulnerability exists in IBM Robotic Process Automation for Cloud Pak, which stems from the fact that it allows users to embed arbitrary JavaScript code in the Web UI to change the intended functionality, potentially leading to a trusted The vulnerability is caused by allowing users to embed arbitrary JavaScript code in the Web UI to change the expected functionality, which could lead to the disclosure of credentials in a trusted session, which could be exploited by an attacker to cause a cross-site scripting attack.

EPSS

0.001

Percentile

26.9%

Related for CNVD-2022-68278