Sensitive Information Disclosure in IBM Robotic Process Automation
CVE-2018-1878

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 November 2018

Summary

IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to a situation where sensitive information may be exposed in a web request. This could potentially assist attackers in formulating future attacks against the system, as they gain insights into the internal workings and data flow of the affected product. Organizations using this software should ensure they implement security measures to mitigate any risks associated with unauthorized data access.

Affected Version(s)

Robotic Process Automation with Automation Anywhere 11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.