Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Robotic Process Automation With Automation Anywhere
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-4901 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2021-05-11 6.4 MEDIUM 6.5 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992.
CVE-2019-4295 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2020-08-24 4.0 MEDIUM 4.9 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758.
CVE-2019-4337 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412.
CVE-2019-4297 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 5.5 MEDIUM 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.
CVE-2019-4299 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 1.9 LOW 4.7 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.
CVE-2018-1908 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 3.5 LOW 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.
CVE-2018-2006 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 4.0 MEDIUM 4.9 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.
CVE-2018-1795 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149073.
CVE-2018-1812 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 3.5 LOW 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the security context of the hosting Web site, once victim opens a certain page in Control Room. IBM X-Force ID: 149883.
CVE-2018-1876 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 2.1 LOW 5.5 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
CVE-2018-1878 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
CVE-2017-1751 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2018-01-05 3.5 LOW 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.