VendorsIBMrobotic_process_automation_for_cloud_pakall versions
Vulnerabilities

IBM Robotic Process Automation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2022-35280
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
Published 2022-08-10 · Modified
9.8EPSS 0.008
CVE-2023-43058
IBM Robotic Process Automation privilege escalation
Published 2023-10-06 · Modified
9.8EPSS 0.006
CVE-2022-43844
IBM Robotic Process Automation for Cloud Pak session fixation
Published 2023-01-05 · Modified
8.8EPSS 0.007
CVE-2023-22592
IBM Robotic Process Automation for Cloud Pak insufficient permission settings
Published 2023-01-18 · Modified
7.8EPSS 0.001
CVE-2022-39168
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.
Published 2022-09-29 · Modified
7.5EPSS 0.008
CVE-2022-43574
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."
Published 2022-11-03 · Modified
7.5EPSS 0.005
CVE-2023-25680
IBM Robotic Process Automation information disclosure
Published 2023-03-15 · Modified
6.5EPSS 0.006
CVE-2023-45189
IBM Robotic Process Automation information disclosure
Published 2023-11-03 · Modified
6.5EPSS 0.005
CVE-2022-46773
IBM Robotic Process Automation security bypass
Published 2023-03-15 · Modified
6.5EPSS 0.005
CVE-2023-23476
IBM Robotic Process Automation information disclosure
Published 2023-08-02 · Modified
6.5EPSS 0.005
CVE-2024-49824
IBM Robotic Process Automation security bypass
Published 2025-01-18 · Analyzed
6.5EPSS 0.003
CVE-2022-36774
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.
Published 2022-10-06 · Modified
6.5EPSS 0.003
CVE-2024-49825
IBM Robotic Process Automation session fixation
Published 2025-04-14 · Analyzed
6.3EPSS 0.002
CVE-2022-38709
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 234291.
Published 2022-10-06 · Modified
6.1EPSS 0.005
CVE-2023-22863
IBM Robotic Process Automation information disclosure
Published 2023-01-18 · Modified
5.9EPSS 0.004
CVE-2022-22502
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124.
Published 2022-06-24 · Modified
5.4EPSS 0.005
CVE-2023-22594
IBM Robotic Process Automation for Cloud Pak cross-site scripting
Published 2023-01-18 · Modified
5.4EPSS 0.004
CVE-2024-51457
IBM Robotic Process Automation for Cloud Pak cross-site scripting
Published 2025-01-22 · Analyzed
5.4EPSS 0.002
CVE-2023-35900
IBM Robotic Process Automation information disclosure
Published 2023-07-19 · Modified
5.3EPSS 0.005
CVE-2023-40370
IBM Robotic Process Automation information disclosure
Published 2023-08-22 · Modified
5.3EPSS 0.005
CVE-2022-43573
IBM Robotic Process Automation information disclosure
Published 2023-01-05 · Modified
5.3EPSS 0.005
CVE-2023-35901
IBM Robotic Process Automation security bypass
Published 2023-07-16 · Modified
5.3EPSS 0.005
CVE-2022-38710
IBM Robotic Process Automation information disclosure
Published 2022-11-03 · Modified
5.3EPSS 0.003
CVE-2022-22490
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
Published 2022-08-10 · Modified
4.9EPSS 0.008
CVE-2022-33953
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
Published 2022-06-24 · Modified
4.6EPSS 0.003
CVE-2022-41740
IBM Robotic Process Automation information disclosure
Published 2023-01-05 · Modified
4.6EPSS 0.002
CVE-2023-38732
IBM Robotic Process Automation information disclosure
Published 2023-08-22 · Modified
4.3EPSS 0.005
CVE-2022-42442
IBM Robotic Process Automation for Cloud Pak information disclosure
Published 2022-11-03 · Modified
3.3EPSS 0.002