PT-2022-6210 · Ibm · Ibm Robotic Process Automation

Published

2022-10-03

·

Updated

2023-08-08

·

CVE-2022-36774

CVSS v3.1

6.5

Medium

VectorC:N/I:H/S:U/UI:N/A:N/PR:N/AV:A/AC:L
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation versions 21.0.0 through 21.0.2
Description The issue is related to the configuration of IBM Robotic Process Automation, which is vulnerable to man-in-the-middle attacks through manipulation of the client proxy configuration. It is also associated with weaknesses in the authentication procedure, allowing a remote attacker to impact the integrity of protected information.
Recommendations For versions 21.0.0 through 21.0.2, consider restricting access to the client proxy configuration to minimize the risk of exploitation. As a temporary workaround, review and secure the authentication procedure to prevent potential manipulation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-00478
CVE-2022-36774

Affected Products

Ibm Robotic Process Automation