CVE-2018-1552: IBM Robotic Process Automation With Automation Anywhere

High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.

IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.

Affected products

  • IBM Robotic Process Automation With Automation Anywhere: version 10 only; version 11 only

Published 2018-11-02. Last modified 2026-06-17.