← volver
CVE-2022-22433

CVE-2022-22433

CVSS 2.7 LOWEPSS 1.0%
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2.7EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
05 may 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 224156.
CVSS:3.0/I:L/AC:L/A:N/S:U/UI:N/AV:N/C:N/PR:H/E:U/RL:O/RC:C

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →