Lucene search

K
ibmIBMD332221DB9D327379D5FB24F5A300D19C646AD99830C055043029F5C4303AFF9
HistoryJun 22, 2022 - 9:43 p.m.

Security Bulletin: IBM Robotic Process Automation is vulnerable to cross-site scripting (CVE-2022-22502)

2022-06-2221:43:47
www.ibm.com
26
ibm robotic process automation
cross-site scripting
cve-2022-22502
vulnerability
fix
update

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.6%

Summary

Security Bulletin: IBM Robotic Process Automation is vulnerable to cross-site scripting (CVE-2022-22502)

Vulnerability Details

CVEID:CVE-2022-22502
**DESCRIPTION:**IBM Robotic Process Automation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/227124 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation as a Service < 21.0.2.2
IBM Robotic Process Automation < 21.0.2.2
IBM Robotic Process Automation < 21.0.1.5
IBM Robotic Process Automation for Cloud Pak < 21.0.2.2

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Remediation/Fixes:

Affected Product(s) Version(s) Fix/Remediation
IBM Robotic Process Automation as a Service < 21.0.2.2 No action required, all SaaS servers are at 21.0.2.5 or higher
IBM Robotic Process Automation < 21.0.2.2 Download and apply IBM Robotic Process Automation 21.0.2 IF003 or higher
IBM Robotic Process Automation < 21.0.1.5 Download and apply IBM Robotic Process Automation 21.0.1 IF005 or higher
IBM Robotic Process Automation for Cloud Pak < 21.0.2.2 Update to IBM Robotic Process Automation 21.0.2.3 or higher

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.1
OR
ibmrobotic_process_automationMatch21.0.2
VendorProductVersionCPE
ibmrobotic_process_automation21.0.1cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*
ibmrobotic_process_automation21.0.2cpe:2.3:a:ibm:robotic_process_automation:21.0.2:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.6%

Related for D332221DB9D327379D5FB24F5A300D19C646AD99830C055043029F5C4303AFF9