Sensitive Information Disclosure in IBM Robotic Process Automation
CVE-2018-1878
5.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 2 November 2018
Summary
IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to a situation where sensitive information may be exposed in a web request. This could potentially assist attackers in formulating future attacks against the system, as they gain insights into the internal workings and data flow of the affected product. Organizations using this software should ensure they implement security measures to mitigate any risks associated with unauthorized data access.
Affected Version(s)
Robotic Process Automation with Automation Anywhere 11
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved