Vulnerability Description
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Robotic Process Automation For Cloud Pak | 21.0.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/230634Broken Link
- https://www.ibm.com/support/pages/node/6610393Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/230634Broken Link
- https://www.ibm.com/support/pages/node/6610393Broken Link
FAQ
What is CVE-2022-35280?
CVE-2022-35280 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Fo...
How severe is CVE-2022-35280?
CVE-2022-35280 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-35280?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Robotic Process Automation For Cloud Pak, Microsoft Windows.