Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.69% | — | IBM Robotic Process Automation FOR Cloud PAK | 5/1/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081. | |
| Modificada | Media (5.3) | 0.47% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 5/1/2023 | 17/6/2026 | IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678. | |
| Modificada | Media (4.6) | 0.20% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 5/1/2023 | 17/6/2026 | IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053. | |
| Modificada | Alta (7.5) | 0.49% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 3/11/2022 | 17/6/2026 | "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679." | |
| Modificada | Baja (3.3) | 0.18% | — | IBM Robotic Process Automation FOR Cloud PAK | 3/11/2022 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of the first tenant owner e-mail address to users with access to the container platform. IBM X-Force ID: 238214. | |
| Modificada | Media (5.3) | 0.31% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 3/11/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292. | |
| Modificada | Media (6.5) | 0.29% | — | IBM Robotic Process Automation | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | |
| Modificada | Media (6.1) | 0.53% | — | IBM Robotic Process Automation FOR Cloud PAK | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.3) | 0.31% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575. | |
| Modificada | Media (6.1) | 0.70% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM… | |
| Modificada | Alta (7.5) | 0.87% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAKIBM Robotic Process Automation FOR Services | 29/9/2022 | 17/6/2026 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. | |
| Modificada | Crítica (9.8) | 0.78% | — | IBM Robotic Process Automation FOR Cloud PAK | 10/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. | |
| Modificada | Media (4.9) | 0.81% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 10/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | |
| Modificada | Media (6.5) | 0.64% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. | |
| Modificada | Media (6.5) | 0.61% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888. | |
| Modificada | Alta (7.2) | 0.94% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978. | |
| Modificada | Alta (7.5) | 0.90% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288. | |
| Modificada | Media (4.3) | 0.50% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391. | |
| Modificada | Media (4.6) | 0.33% | — | IBM Robotic Process Automation | 26/7/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019. | |
| Modificada | Media (4.6) | 0.27% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 24/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 24/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124. | |
| Modificada | Media (5.5) | 0.22% | — | IBM Robotic Process Automation | 20/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. | |
| Modificada | Media (6.5) | 0.74% | — | IBM Robotic Process Automation | 17/6/2022 | 17/6/2026 | IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294. | |
| Modificada | Crítica (9.8) | 1.3% | — | IBM Robotic Process Automation | 12/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022. | |
| Modificada | Media (5.4) | 1.0% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 9/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. |