5.9

CVE-2023-22863

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL.  This could allow an attacker to obtain sensitive information using man in the middle techniques.  IBM X-Force ID:  244109.

Data is provided by the National Vulnerability Database (NVD)
IbmRobotic Process Automation Version < 21.0.3
   MicrosoftWindows Version-
   RedhatOpenshift Version-
IbmRobotic Process Automation As A Service Version < 21.0.3
   MicrosoftWindows Version-
   RedhatOpenshift Version-
IbmRobotic Process Automation For Cloud Pak Version < 21.0.3
   MicrosoftWindows Version-
   RedhatOpenshift Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.034
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.