Lucene search

K
cvelistIbmCVELIST:CVE-2022-22414
HistoryJun 20, 2022 - 4:25 p.m.

CVE-2022-22414

2022-06-2016:25:17
ibm
www.cve.org
4
ibm robotic process automation
sensitive data exposure
system memory

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.

CNA Affected

[
  {
    "product": "Robotic Process Automation",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "21.0.2"
      }
    ]
  }
]

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2022-22414