Show filters
72 Total Results
Displaying 61-70 of 72
Sort by:
Attacker Value
Unknown

CVE-2019-11875

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information. The attack requires a valid user account to connect to the Blue Prism server, but the roles associated to this account are not required to have any permissions. First of all, the application files are modified to grant full permissions on the client side. In a test environment (or his own instance of the software) an attacker is able to grant himself full privileges also on the server side. He can then, for instance, create a process with malicious behavior and export it to disk. With the modified client, it is possible to import the exported file as a release and overwrite any existing process in the database. Eventually, the bots execute the malicious process. The server does not check the user's permissions for the aforementi…
0
Attacker Value
Unknown

CVE-2018-1908

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.
0
Attacker Value
Unknown

CVE-2018-2006

Disclosure Date: February 21, 2019 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.
0
Attacker Value
Unknown

CVE-2018-1877

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.
0
Attacker Value
Unknown

CVE-2018-1552

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.
0
Attacker Value
Unknown

CVE-2018-1878

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
0
Attacker Value
Unknown

CVE-2018-1876

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
0
Attacker Value
Unknown

CVE-2018-1812

Disclosure Date: October 05, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the security context of the hosting Web site, once victim opens a certain page in Control Room. IBM X-Force ID: 149883.
0
Attacker Value
Unknown

CVE-2018-1795

Disclosure Date: October 05, 2018 (last updated November 27, 2024)
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149073.
0
Attacker Value
Unknown

CVE-2018-1547

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.
0