PT-2021-12223 · Ibm · Ibm Robotic Process Automation With Automation Anywhere
Jhonatan Huallanca
·
Published
2021-05-07
·
Updated
2021-05-11
·
CVE-2020-4901
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
IBM Robotic Process Automation with Automation Anywhere version 11.0
Description
The issue allows an attacker on the network to obtain sensitive information or cause a denial of service through
username enumeration.Recommendations
For IBM Robotic Process Automation with Automation Anywhere version 11.0, consider restricting access to sensitive information and implementing measures to prevent denial of service attacks until a fix is available. As a temporary workaround, avoid using the
username enumeration feature to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Robotic Process Automation With Automation Anywhere