PT-2019-17020 · Automation Anywhere+1 · Automation Anywhere+1

Published

2019-07-01

·

Updated

2023-02-03

·

CVE-2019-4296

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation with Automation Anywhere version 11
Description The issue allows a local user to obtain e-mail contents from the client debug log file, potentially leading to information disclosure.
Recommendations For IBM Robotic Process Automation with Automation Anywhere version 11, consider restricting access to the client debug log file to minimize the risk of exploitation. As a temporary workaround, limit local user privileges to prevent unauthorized access to sensitive information.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2019-4296

Affected Products

Automation Anywhere
Ibm Robotic Process Automation