IBM Robotic Process Automation with Automation Anywhere is vulnerable to cross-site request forgery.
CV****EID: CVE-2018-1514**
DESCRIPTION:** IBM Robotic Process Automation with Automation Anywhere is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/141622> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
- IBM Robotic Process Automation with Automation Anywhere V10.0.0.0
The recommended solution is to apply the interim fix containing APAR JR59510 as soon as practical:
- IBM Robotic Process Automation with Automation Anywhere
None