PT-2022-6214 · Ibm · Ibm Robotic Process Automation

Published

2022-10-06

·

Updated

2022-11-08

·

CVE-2022-22503

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation version 21.0.0
Description The issue is related to errors in the representation of information by the user interface. It could allow a remote attacker to hijack the clicking action of the victim by persuading them to visit a malicious web site, potentially launching further attacks. This could impact the confidentiality and integrity of protected information.
Recommendations For IBM Robotic Process Automation version 21.0.0, consider restricting access to the software until a patch is available to prevent remote attackers from hijacking the victim's click actions. As a temporary workaround, avoid using the software to interact with untrusted web sites to minimize the risk of exploitation.

Fix

Clickjacking

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2023-00482
CVE-2022-22503

Affected Products

Ibm Robotic Process Automation