PT-2022-6210 · Ibm · Ibm Robotic Process Automation
Published
2022-10-03
·
Updated
2023-08-08
·
CVE-2022-36774
CVSS v3.1
6.5
Medium
| Vector | C:N/I:H/S:U/UI:N/A:N/PR:N/AV:A/AC:L |
Name of the Vulnerable Software and Affected Versions
IBM Robotic Process Automation versions 21.0.0 through 21.0.2
Description
The issue is related to the configuration of IBM Robotic Process Automation, which is vulnerable to man-in-the-middle attacks through manipulation of the client proxy configuration. It is also associated with weaknesses in the authentication procedure, allowing a remote attacker to impact the integrity of protected information.
Recommendations
For versions 21.0.0 through 21.0.2, consider restricting access to the client proxy configuration to minimize the risk of exploitation.
As a temporary workaround, review and secure the authentication procedure to prevent potential manipulation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Robotic Process Automation