CVE-2022-35280: IBM Robotic Process Automation For Cloud Pak

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.

Affected products

  • IBM Robotic Process Automation For Cloud Pak: version 21.0.0 only; version 21.0.1 only; version 21.0.2 only

Published 2022-08-10. Last modified 2026-06-17.