Cross-Site Scripting in IBM Robotic Process Automation with Automation Anywhere Enterprise 10
CVE-2018-1795

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 October 2018

Summary

IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is susceptible to a cross-site scripting flaw, which enables malicious users to inject arbitrary JavaScript code into the web interface. This vulnerability could allow an attacker to manipulate the web application’s behavior, potentially leading to the unauthorized disclosure of credentials during a trusted session.

Affected Version(s)

Robotic Process Automation with Automation Anywhere 10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.