CVE-2022-35280

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

13 Aug 2022, 00:16

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-521
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/230634 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/230634 - Broken Link
References (CONFIRM) https://www.ibm.com/support/pages/node/6610393 - (CONFIRM) https://www.ibm.com/support/pages/node/6610393 - Broken Link

10 Aug 2022, 20:15

Type Values Removed Values Added
Summary IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.

10 Aug 2022, 17:53

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-10 17:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-35280

Mitre link : CVE-2022-35280

CVE.ORG link : CVE-2022-35280


JSON object : View

Products Affected

microsoft

  • windows

ibm

  • robotic_process_automation_for_cloud_pak
CWE
CWE-521

Weak Password Requirements