PT-2023-18737 · Ibm · Ibm Robotic Process Automation

Published

2023-01-18

·

Updated

2023-01-27

·

CVE-2023-22863

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Robotic Process Automation versions 20.12.0 through 21.0.2
Description The issue allows an attacker to obtain sensitive information using man-in-the-middle techniques because some RPA commands default to HTTP when the prefix is not explicitly specified in the URL.
Recommendations For versions 20.12.0 through 21.0.2, ensure that all RPA commands explicitly specify the URL prefix to use a secure protocol, such as HTTPS, to prevent man-in-the-middle attacks. As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-22863

Affected Products

Ibm Robotic Process Automation