CVE-2022-46773: IBM Robotic Process Automation
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
Affected products
- IBM Robotic Process Automation: from 21.0.0, before 21.0.7.1 (fixed in 21.0.7.1); version 23.0.0 only
- IBM Robotic Process Automation As A Service: before 23.0.1 (fixed in 23.0.1)
- IBM Robotic Process Automation For Cloud Pak: from 21.0.0, before 21.0.7.1 (fixed in 21.0.7.1); version 23.0.0 only
Published 2023-03-15. Last modified 2026-06-17.