Page 10 of 66 results (0.007 seconds)

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 224156. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, es vulnerable a un ataque de Interacción de Servicios Externos, causado por la comprobación inapropiada de la entrada suministrada por el usuario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/224156 https://www.ibm.com/support/pages/node/6573913 • CWE-20: Improper Input Validation •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. Se presenta una vulnerabilidad por la que un usuario habitual de IBM Robotic Process Automation versión 21.0.1, puede obtener acceso de sólo lectura a algunas páginas de administración en el Centro de IBM X-Force ID: 223029 • https://exchange.xforce.ibmcloud.com/vulnerabilities/223029 https://www.ibm.com/support/pages/node/6570235 •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992. IBM Robotic Process Automation con Automation Anywhere versión 11.0, podría permitir a un atacante en la red obtener información confidencial o causar una denegación de servicio mediante la enumeración de nombres de usuario.  IBM X-Force ID: 190992 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190992 https://www.ibm.com/support/pages/node/6450435 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. IBM Robotic Process Automation with Automation Anywhere versión 11 podría permitir a un atacante obtener información sensible debido a la falta de autenticación en Ignite nodes. ID de IBM X-Force: 161412. • http://www.ibm.com/support/docview.wss?uid=ibm10884850 https://exchange.xforce.ibmcloud.com/vulnerabilities/161412 • CWE-306: Missing Authentication for Critical Function •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411. IBM Robotic Process Automation with Automation Anywhere versión 11 emplea una configuración de bloqueo de cuenta inadecuada que podría permitir que un atacante remoto descifre credenciales de cuenta por fuerza bruta. ID de IBM X-Force:161411. • http://www.ibm.com/support/docview.wss?uid=ibm10884848 https://exchange.xforce.ibmcloud.com/vulnerabilities/161411 • CWE-307: Improper Restriction of Excessive Authentication Attempts •