Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
IBM Robotic Process Automation session fixation
Vulnerability Description
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
IBM Robotic Process Automation 代码问题漏洞
Vulnerability Description
IBM Robotic Process Automation是美国国际商业机器(IBM)公司的一种机器人流程自动化产品。可帮助您以传统 RPA 的轻松和速度大规模自动化更多业务和 IT 流程。 IBM Robotic Process Automation 21.0.1至21.0.7版本、23.0.0至23.0.1版本存在代码问题漏洞,该漏洞源于会话令牌在密码重置后不会失效,击者利用该漏洞可以进入系统。
CVSS Information
N/A
Vulnerability Type
N/A