Lucene search

K
cve[email protected]CVE-2022-46773
HistoryMar 15, 2023 - 8:15 p.m.

CVE-2022-46773

2023-03-1520:15:10
CWE-287
web.nvd.nist.gov
24
ibm
rpa
robotic process automation
cve-2022-46773
security
vulnerability
client-side validation
credential pools

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.

Affected configurations

Vulners
NVD
Node
ibmrobotic_process_automationRange21.0.021.0.7
OR
ibmrobotic_process_automationMatch23.0.0
VendorProductVersionCPE
ibmrobotic_process_automation*cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*
ibmrobotic_process_automation23.0.0cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Robotic Process Automation",
    "vendor": "IBM",
    "versions": [
      {
        "lessThan": "21.0.7",
        "status": "affected",
        "version": "21.0.0",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "23.0.0"
      }
    ]
  }
]

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

Related for CVE-2022-46773