Vulnerabilities > IBM > Robotic Process Automation FOR Cloud PAK

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2022-39168 Insufficiently Protected Credentials vulnerability in IBM products
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs.
network
low complexity
ibm CWE-522
7.5
2022-08-10 CVE-2022-22490 Files or Directories Accessible to External Parties vulnerability in IBM products
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information.
network
low complexity
ibm CWE-552
4.9
2022-08-10 CVE-2022-35280 Weak Password Requirements vulnerability in IBM Robotic Process Automation for Cloud PAK 21.0.0/21.0.1/21.0.2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2022-06-24 CVE-2022-22502 Cross-site Scripting vulnerability in IBM products
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-06-24 CVE-2022-33953 Insufficiently Protected Credentials vulnerability in IBM products
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens.
low complexity
ibm CWE-522
4.6