
CVE-2022-35280
https://notcve.org/view.php?id=CVE-2022-35280
10 Aug 2022 — IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, no exige que usuarios tengan contraseñas seguras por defecto, lo que facilita que atacantes puedan comprometer las cuentas de usuarios. IBM X-Force ID: 230634 • https://exchange.xforce.ibmcloud.com/vulnerabilities/230634 • CWE-521: Weak Password Requirements •

CVE-2022-22490
https://notcve.org/view.php?id=CVE-2022-22490
10 Aug 2022 — IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, podría permitir a un usuario privilegiado obtener información confidencial de credenciales del bot de Azure. IBM X-Force ID: 226342 • https://exchange.xforce.ibmcloud.com/vulnerabilities/226342 • CWE-552: Files or Directories Accessible to External Parties •

CVE-2022-33953
https://notcve.org/view.php?id=CVE-2022-33953
24 Jun 2022 — IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, podría permitir a un usuario con acceso psíquico al sistema obtener información confidencial debido a tokens de acceso insuficientemente protegidos. IBM X-Force ID: 229198 • https://exchange.xforce.ibmcloud.com/vulnerabilities/229198 • CWE-522: Insufficiently Protected Credentials •

CVE-2022-22502
https://notcve.org/view.php?id=CVE-2022-22502
24 Jun 2022 — IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227124 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-29859
https://notcve.org/view.php?id=CVE-2021-29859
02 May 2022 — IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user with physical access to the system to perform unauthorized actions or obtain sensitive information due to insufficient validation and recvocation another user logouting out. IBM X-Force ID: 206081. IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation versiones V21.0.3 hasta V21.0.... • https://exchange.xforce.ibmcloud.com/vulnerabilities/206081 •

CVE-2021-29872
https://notcve.org/view.php?id=CVE-2021-29872
18 Jan 2022 — IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 206228. IBM Cloud Pak for Au... • https://exchange.xforce.ibmcloud.com/vulnerabilities/206228 • CWE-116: Improper Encoding or Escaping of Output •

CVE-2021-38966
https://notcve.org/view.php?id=CVE-2021-38966
21 Dec 2021 — IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212357. IBM Cloud Pak for Automation versión 21.0.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212357 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-29775
https://notcve.org/view.php?id=CVE-2021-29775
28 Jun 2021 — IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203029. IBM Business Automation Workflow versiones 19.0.03 y 20.0 e IBM Cloud Pak for Automation versiones 20.0.3-IF002 y 21.0.1, son vulnerables a ataques... • https://exchange.xforce.ibmcloud.com/vulnerabilities/203029 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-20482
https://notcve.org/view.php?id=CVE-2021-20482
30 Mar 2021 — IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197504. IBM Cloud Pak for Automation versiones 20.0.2 y 20.0.3 IF002, son vulnerables a un ataque de tipo External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer infor... • https://exchange.xforce.ibmcloud.com/vulnerabilities/197504 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2021-20359
https://notcve.org/view.php?id=CVE-2021-20359
08 Feb 2021 — IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966. IBM Cloud Pak for Automation versiones 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component, almacena información potencialmente confidencial en archivos de registro que podría obtener un usuario no autorizado. IBM X-Force ID: 194966 • https://exchange.xforce.ibmcloud.com/vulnerabilities/194966 • CWE-532: Insertion of Sensitive Information into Log File •