CVE-2022-22503
- EPSS 0.22%
- Published 06.10.2022 18:15:52
- Last modified 21.11.2024 06:46:54
IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click act...
CVE-2022-22490
- EPSS 0.26%
- Published 10.08.2022 17:15:08
- Last modified 21.11.2024 06:46:53
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
CVE-2022-33953
- EPSS 0.05%
- Published 24.06.2022 16:15:10
- Last modified 21.11.2024 07:08:40
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
CVE-2022-22502
- EPSS 0.22%
- Published 24.06.2022 16:15:09
- Last modified 21.11.2024 06:46:54
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl...
CVE-2022-22319
- EPSS 0.31%
- Published 09.05.2022 17:15:09
- Last modified 21.11.2024 06:46:38
IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366.
CVE-2022-22433
- EPSS 0.25%
- Published 05.05.2022 16:15:10
- Last modified 21.11.2024 06:46:47
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform serve...
CVE-2022-22434
- EPSS 0.05%
- Published 05.05.2022 16:15:10
- Last modified 21.11.2024 06:46:47
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159.