Automation Anywhere · Automation Anywhere · CVE-2018-2006
**Name of the Vulnerable Software and Affected Versions**
IBM Robotic Process Automation with Automation Anywhere version 11
**Description**
The issue allows a remote attacker to traverse directories on the system by sending a specially-crafted URL request containing `dot dot` sequences (`/../`) to upload arbitrary files to the system.
**Recommendations**
For IBM Robotic Process Automation with Automation Anywhere version 11, consider restricting access to the affected URL endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using URL requests with `dot dot` sequences (`/../`) until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.