CVE-2022-22433
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 224156.
IBM Robotic Process Automation versiones 21.0.1 y 21.0.2, es vulnerable a un ataque de Interacción de Servicios Externos, causado por la comprobación inapropiada de la entrada suministrada por el usuario. Un atacante remoto podría aprovechar esta vulnerabilidad para inducir a la aplicación a llevar a cabo búsquedas DNS del lado del servidor o peticiones HTTP a nombres de dominio arbitrarios. Al enviar cargas útiles adecuadas, un atacante puede causar que el servidor de aplicaciones ataque otros sistemas con los que pueda interactuar. IBM X-Force ID: 224156
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-03 CVE Reserved
- 2022-05-05 CVE Published
- 2023-11-26 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/pages/node/6573913 | 2022-05-16 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/224156 | 2022-05-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Robotic Process Automation Search vendor "Ibm" for product "Robotic Process Automation" | < 21.0.1.5 Search vendor "Ibm" for product "Robotic Process Automation" and version " < 21.0.1.5" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Ibm Search vendor "Ibm" | Robotic Process Automation Search vendor "Ibm" for product "Robotic Process Automation" | 21.0.2 Search vendor "Ibm" for product "Robotic Process Automation" and version "21.0.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Ibm Search vendor "Ibm" | Robotic Process Automation As A Service Search vendor "Ibm" for product "Robotic Process Automation As A Service" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|