VulnerabilityModified
CVE-2022-36774
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration.
MEDIUM 5.3EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Affected
- ibm/robotic process automation · ibm/robotic process automation as a service · ibm/robotic process automation for cloud pak
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/233575VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6826013Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/233575VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6826013Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.