IBM RPA login token leak 21.0.021.0.2 localhost auth bypass
CVE-2022-22412 Published on July 26, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019.
Products Associated with CVE-2022-22412
Want to know whenever a new CVE is published for IBM Robotic Process Automation? stack.watch will email you.
Affected Versions
IBM Robotic Process Automation:- Version 21.0.0 is affected.
- Version 21.0.1 is affected.
- Version 21.0.2 is affected.
Exploit Probability
EPSS
0.09%
Percentile
24.49%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.