CVE-2023-22863: IBM Robotic Process Automation
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 244109.
Affected products
- IBM Robotic Process Automation: before 21.0.3 (fixed in 21.0.3)
- IBM Robotic Process Automation As A Service: before 21.0.3 (fixed in 21.0.3)
- IBM Robotic Process Automation For Cloud Pak: before 21.0.3 (fixed in 21.0.3)
Published 2023-01-18. Last modified 2026-06-17.