CVE Vulnerabilities

CVE-2024-51456

Use of RSA Algorithm without OAEP

Published: Jan 12, 2025 | Modified: Mar 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.

Weakness

The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.

Affected Software

Name Vendor Start Version End Version
Robotic_process_automation Ibm 21.0.0 (including) 21.0.7.19 (including)
Robotic_process_automation Ibm 23.0.0 (including) 23.0.19 (including)

References