CVE-2022-22505
https://notcve.org/view.php?id=CVE-2022-22505
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, contiene una vulnerabilidad que podría permitir la exposición de las credenciales de los inquilinos de IBM. IBM X-Force ID: 227288 • https://exchange.xforce.ibmcloud.com/vulnerabilities/227288 https://www.ibm.com/support/pages/node/6608404 •
CVE-2022-22334
https://notcve.org/view.php?id=CVE-2022-22334
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, podría permitir a un usuario acceder a información de un tenant a la que no debería tener acceso. IBM X-Force ID: 219391 • https://exchange.xforce.ibmcloud.com/vulnerabilities/219391 https://www.ibm.com/support/pages/node/6608550 •
CVE-2022-22412
https://notcve.org/view.php?id=CVE-2022-22412
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019. IBM Robotic Process Automation versiones 21.0.0, 21.0.1 y 21.0.2, podrían permitir a un usuario con acceso al host local (máquina cliente) obtener un token de acceso de inicio de sesión. IBM X-Force ID: 223019. • https://exchange.xforce.ibmcloud.com/vulnerabilities/223019 https://www.ibm.com/support/pages/node/6607045 •
CVE-2022-33953
https://notcve.org/view.php?id=CVE-2022-33953
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, podría permitir a un usuario con acceso psíquico al sistema obtener información confidencial debido a tokens de acceso insuficientemente protegidos. IBM X-Force ID: 229198 • https://exchange.xforce.ibmcloud.com/vulnerabilities/229198 https://www.ibm.com/support/pages/node/6597669 • CWE-522: Insufficiently Protected Credentials •
CVE-2022-22502
https://notcve.org/view.php?id=CVE-2022-22502
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124. IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista y conllevando potencialmente a una divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/227124 https://www.ibm.com/support/pages/node/6597667 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •