Remote Code Execution Vulnerability in IBM Robotic Process Automation
CVE-2018-1552

5.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 November 2018

Summary

IBM Robotic Process Automation with Automation Anywhere versions 10.0 and 11.0 contains a security weakness due to inadequate restrictions on file uploads to the control room. This flaw allows remote attackers to upload malicious files that could be executed by unsuspecting users, enabling the attackers to run arbitrary code on the targeted systems. Such exploitation poses significant risks to data integrity and operational continuity.

Affected Version(s)

Robotic Process Automation with Automation Anywhere 10.0

Robotic Process Automation with Automation Anywhere 11.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.