Remote Code Execution Vulnerability in IBM Robotic Process Automation
CVE-2018-1547
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 7 June 2018
What is CVE-2018-1547?
A vulnerability in IBM Robotic Process Automation with Automation Anywhere 10.0 allows remote attackers to execute arbitrary code by exploiting improper output encoding during CSV exports. Attackers can lure victims into downloading the malicious CSV file, prompting them to open it in Microsoft Excel. By confirming two security questions, they can execute commands or run programs on the victim's machine without their consent. Organizations using this software must ensure their systems are patched to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Robotic Process Automation with Automation Anywhere 10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved