Persistent Cross-Site Scripting in IBM Robotic Process Automation
CVE-2018-1812
5.4MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 5 October 2018
Summary
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 has a vulnerability that allows for persistent cross-site scripting (XSS) attacks. This arises from insufficient escaping of data in a database field. An attacker with access to the Control Room database can exploit this flaw to run malicious scripts in a victim's web browser when the victim navigates to a specific page within the Control Room interface, potentially compromising the integrity of the application and the security of the user.
Affected Version(s)
Robotic Process Automation with Automation Anywhere 10
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved