IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Robotic_process_automation | Ibm | * | 21.0.2.5 (excluding) |
Robotic_process_automation_as_a_service | Ibm | * | 21.0.2.5 (excluding) |
Robotic_process_automation_for_cloud_pak | Ibm | * | 21.0.2.5 (excluding) |