CVE-2022-46773: IBM Robotic Process Automation

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.

Affected products

  • IBM Robotic Process Automation: from 21.0.0, before 21.0.7.1 (fixed in 21.0.7.1); version 23.0.0 only
  • IBM Robotic Process Automation As A Service: before 23.0.1 (fixed in 23.0.1)
  • IBM Robotic Process Automation For Cloud Pak: from 21.0.0, before 21.0.7.1 (fixed in 21.0.7.1); version 23.0.0 only

Published 2023-03-15. Last modified 2026-06-17.