Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—IBM Robotic Process Automation With Automation Anywhere7/5/202117/6/2026
IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992.
ModificadaMedia (5.3)1.4%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412.
ModificadaCrítica (9.8)2.0%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.
ModificadaMedia (5.5)0.28%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.
ModificadaAlta (7.1)0.32%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764.
ModificadaMedia (5.4)1.1%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.
ModificadaBaja (3.3)0.30%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.
ModificadaMedia (4.9)1.1%—IBM Robotic Process Automation With Automation Anywhere1/7/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758.
ModificadaMedia (5.4)0.97%—IBM Robotic Process Automation With Automation Anywhere14/3/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.
ModificadaMedia (4.9)2.5%—IBM Robotic Process Automation With Automation Anywhere21/2/201917/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.
ModificadaMedia (5.3)1.3%—IBM Robotic Process Automation With Automation Anywhere2/11/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
ModificadaAlta (7.8)0.24%—IBM Robotic Process Automation With Automation Anywhere2/11/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.
ModificadaMedia (5.5)0.37%—IBM Robotic Process Automation With Automation Anywhere2/11/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
ModificadaAlta (8.8)2.9%—IBM Robotic Process Automation With Automation Anywhere2/11/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this…
ModificadaMedia (5.4)0.66%—IBM Robotic Process Automation With Automation Anywhere5/10/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the…
ModificadaMedia (6.1)0.89%—IBM Robotic Process Automation With Automation Anywhere5/10/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…
ModificadaAlta (7.7)2.0%—IBM Robotic Process Automation With Automation Anywhere7/6/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an…
ModificadaAlta (8.8)0.53%—IBM Robotic Process Automation With Automation Anywhere7/6/201817/6/2026
IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 141622.
ModificadaMedia (5.4)0.69%—IBM Robotic Process Automation With Automation Anywhere20/12/201717/6/2026
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.