
CVE-2022-22503
https://notcve.org/view.php?id=CVE-2022-22503
06 Oct 2022 — IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 227125. IBM Robotic Process Automation 21.0.0, podría permitir a un atacante remoto secuestrar la acción de hacer clic de la víctima. Al persuadir a una víctima para que visite un sitio... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227125 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVE-2022-22490
https://notcve.org/view.php?id=CVE-2022-22490
10 Aug 2022 — IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, podría permitir a un usuario privilegiado obtener información confidencial de credenciales del bot de Azure. IBM X-Force ID: 226342 • https://exchange.xforce.ibmcloud.com/vulnerabilities/226342 • CWE-552: Files or Directories Accessible to External Parties •

CVE-2022-33953
https://notcve.org/view.php?id=CVE-2022-33953
24 Jun 2022 — IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, podría permitir a un usuario con acceso psíquico al sistema obtener información confidencial debido a tokens de acceso insuficientemente protegidos. IBM X-Force ID: 229198 • https://exchange.xforce.ibmcloud.com/vulnerabilities/229198 • CWE-522: Insufficiently Protected Credentials •

CVE-2022-22502
https://notcve.org/view.php?id=CVE-2022-22502
24 Jun 2022 — IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227124 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-22319
https://notcve.org/view.php?id=CVE-2022-22319
09 May 2022 — IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. IBM Robotic Process Automation versión 21.0.1, podría permitir que un usuario registrado en el sistema eliminara físicamente una cola, lo que podría causar la interrupción de cualquier script dependiente de la cola. IBM X-Force ID: 218366 • https://exchange.xforce.ibmcloud.com/vulnerabilities/218366 •

CVE-2022-22434
https://notcve.org/view.php?id=CVE-2022-22434
05 May 2022 — IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, podrían permitir a un usuario con acceso físico crear una petición de API modificada para crear objetos adicionales. IBM X-Force ID: 224159 • https://exchange.xforce.ibmcloud.com/vulnerabilities/224159 •

CVE-2022-22433
https://notcve.org/view.php?id=CVE-2022-22433
05 May 2022 — IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 224156. IBM Robotic Process Automation versiones 21.0.... • https://exchange.xforce.ibmcloud.com/vulnerabilities/224156 • CWE-20: Improper Input Validation •