PT-2022-6214 · Ibm · Ibm Robotic Process Automation
Published
2022-10-06
·
Updated
2022-11-08
·
CVE-2022-22503
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Robotic Process Automation version 21.0.0
Description
The issue is related to errors in the representation of information by the user interface. It could allow a remote attacker to hijack the clicking action of the victim by persuading them to visit a malicious web site, potentially launching further attacks. This could impact the confidentiality and integrity of protected information.
Recommendations
For IBM Robotic Process Automation version 21.0.0, consider restricting access to the software until a patch is available to prevent remote attackers from hijacking the victim's click actions. As a temporary workaround, avoid using the software to interact with untrusted web sites to minimize the risk of exploitation.
Fix
Clickjacking
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Robotic Process Automation