PT-2023-18737 · Ibm · Ibm Robotic Process Automation
Published
2023-01-18
·
Updated
2023-01-27
·
CVE-2023-22863
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Robotic Process Automation versions 20.12.0 through 21.0.2
Description
The issue allows an attacker to obtain sensitive information using man-in-the-middle techniques because some RPA commands default to HTTP when the prefix is not explicitly specified in the URL.
Recommendations
For versions 20.12.0 through 21.0.2, ensure that all RPA commands explicitly specify the URL prefix to use a secure protocol, such as HTTPS, to prevent man-in-the-middle attacks. As a temporary workaround, consider restricting access to sensitive information until a patch is available.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Robotic Process Automation