PT-2021-12223 · Ibm · Ibm Robotic Process Automation With Automation Anywhere

Jhonatan Huallanca

·

Published

2021-05-07

·

Updated

2021-05-11

·

CVE-2020-4901

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation with Automation Anywhere version 11.0
Description The issue allows an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration.
Recommendations For IBM Robotic Process Automation with Automation Anywhere version 11.0, consider restricting access to sensitive information and implementing measures to prevent denial of service attacks until a fix is available. As a temporary workaround, avoid using the username enumeration feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-4901

Affected Products

Ibm Robotic Process Automation With Automation Anywhere