Persistent Cross-Site Scripting in IBM Robotic Process Automation
CVE-2018-1812

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 October 2018

Summary

IBM Robotic Process Automation with Automation Anywhere Enterprise 10 has a vulnerability that allows for persistent cross-site scripting (XSS) attacks. This arises from insufficient escaping of data in a database field. An attacker with access to the Control Room database can exploit this flaw to run malicious scripts in a victim's web browser when the victim navigates to a specific page within the Control Room interface, potentially compromising the integrity of the application and the security of the user.

Affected Version(s)

Robotic Process Automation with Automation Anywhere 10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.