CVE-2019-4297: IBM Robotic Process Automation With Automation Anywhere

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.

Affected products

  • IBM Robotic Process Automation With Automation Anywhere: from 11.0.0.0, before 11.0.0.5 (fixed in 11.0.0.5)

Published 2019-07-01. Last modified 2026-06-17.