Improper Authentication in IBM Robotic Process Automation - CVE-2022-46773
Published: October 16, 2023
Vulnerability identifier: #VU82037
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46773
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote user can bypass authentication process and gain unauthorized access to the application.
Affected software
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2022-46773
Install updates from vendor's website.
IBM Robotic Process Automation - addressed in versions 21.0.7.1, 23.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.2