Lucene search

K
ibmIBM06A8173704B38D58B194AC5AD54754D62586055C3B772D6FF89A15EA484269AF
HistoryJul 29, 2022 - 5:00 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to an information disclosure (CVE-2022-22334)

2022-07-2917:00:02
www.ibm.com
57
ibm robotic process automation
information disclosure
cve-2022-22334
vulnerability
fix
version
security bulletin

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

19.6%

Summary

Security Bulletin: IBM Robotic Process Automation is vulnerable to an information disclosure (CVE-2022-22334)

Vulnerability Details

CVEID:CVE-2022-22334
**DESCRIPTION:**IBM Robotic Process Automation could allow a user to access information from a tenant of which they should not have access.
CVSS Base score: 4.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/219391 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation as a Service All
IBM Robotic Process Automation < 21.0.2.5
IBM Robotic Process Automation < 21.0.1.7

Remediation/Fixes

** IBM strongly recommends addressing the vulnerability now.**

Product(s)|**Version(s)
**|Remediation/Fix/Instructions
—|—|—
IBM Robotic Process Automation| 21.0.2|

Download and install 21.0.2.5 (21.0.2 IF005)

IBM Robotic Process Automation| 21.0.1| Download and install 21.0.1.7 (21.0.1 IF007)
IBM Robotic Process Automation as a Service| All| No action required as IBM Robotic Process Automation as a Service servers have been updated to 21.0.2 IF005 or higher.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.1
OR
ibmrobotic_process_automationMatch21.0.2
VendorProductVersionCPE
ibmrobotic_process_automation21.0.0cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.1cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.2cpe:2.3:a:ibm:robotic_process_automation:21.0.2:*:*:*:*:*:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

19.6%

Related for 06A8173704B38D58B194AC5AD54754D62586055C3B772D6FF89A15EA484269AF