Lucene search

K
nvd[email protected]NVD:CVE-2022-46773
HistoryMar 15, 2023 - 8:15 p.m.

CVE-2022-46773

2023-03-1520:15:10
CWE-287
web.nvd.nist.gov
1
ibm robotic process automation
client-side validation
credential pools

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.0%

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.

Affected configurations

NVD
Node
ibmrobotic_process_automationRange21.0.021.0.7.1
OR
ibmrobotic_process_automationMatch23.0.0
OR
ibmrobotic_process_automation_as_a_serviceRange<23.0.1
OR
ibmrobotic_process_automation_for_cloud_pakRange21.0.021.0.7.1
OR
ibmrobotic_process_automation_for_cloud_pakMatch23.0.0

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.0%

Related for NVD:CVE-2022-46773