19 results (0.003 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

07 May 2021 — IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992. IBM Robotic Process Automation con Automation Anywhere versión 11.0, podría permitir a un atacante en la red obtener información confidencial o causar una denegación de servicio mediante la enumeración de nombres de usuario.  IBM X-Force ID: 190992 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190992 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. IBM Robotic Process Automation with Automation Anywhere versión 11 podría permitir a un atacante obtener información sensible debido a la falta de autenticación en Ignite nodes. ID de IBM X-Force: 161412. • http://www.ibm.com/support/docview.wss?uid=ibm10884850 • CWE-306: Missing Authentication for Critical Function •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411. IBM Robotic Process Automation with Automation Anywhere versión 11 emplea una configuración de bloqueo de cuenta inadecuada que podría permitir que un atacante remoto descifre credenciales de cuenta por fuerza bruta. ID de IBM X-Force:161411. • http://www.ibm.com/support/docview.wss?uid=ibm10884848 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765. IBM Robotic Process Automation with Automation Anywhere versión 11 podría permitir que un usuario local obtenga información altamente sensible de los archivos de registro cuando la depuración está habilitada. ID de IBM X-Force: 160765. • http://www.ibm.com/support/docview.wss?uid=ibm10884842 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 7.7EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764. IBM Robotic Process Automation with Automation Anywhere versión 11 utiiliza una cuenta de PostgreSQL de alto privilegio para el acceso a la base de datos que podría permitir a un usuario local realizar acciones que no deberían tener privilegios para ejecutar. ID de IBM X-F... • http://www.ibm.com/support/docview.wss?uid=ibm10884820 •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761. IBM Robotic Process Automation with Automation Anywhere versión 11 podría permitir que un atacante remoto autenticado realizar un ataque de inyección LDAP. Mediante el uso de una petición especialmente manipulada, u... • http://www.ibm.com/support/docview.wss?uid=ibm10884826 • CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') •

CVSS: 4.0EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759. IBM Robotic Process Automation with Automation Anywhere versión 11 una divulgación de información podría permitir a un usuario local obtener contenidos de correo electrónico del archivo de registro de depuración del cliente. ID de IBM X-Force: 160759. • http://www.ibm.com/support/docview.wss?uid=ibm10884844 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 4.9EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2019 — IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758. IBM Robotic Process Automation with Automation Anywhere versión 11 podría permitir que un atacante con acceso especializado obtener información altamente confidencial de la bóveda de credenciales. ID de IBM X-Force: 160758. • http://www.ibm.com/support/docview.wss?uid=ibm10884840 •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

14 Mar 2019 — IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671. IBM Robotic Process Automation with Automation Anywhere 11 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de... • http://www.ibm.com/support/docview.wss?uid=ibm10739253 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.9EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008. IBM Robotic Process Automation, en su versión "Automation Anywhere 11", podría permitir que un atacante remoto salte directorios en el sistema. Un atacante podría enviar una petición URL especialmente manipulada que contenga s... • http://www.securityfocus.com/bid/107122 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •