Robotic Process Automation

Vendor:

First CVE: May 5, 2022 · Active for 4 years

46
Total CVEs
More Total CVEs than 98% of tracked products
11.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Robotic Process Automation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2022
4 years ago
Most Recent CVE
Apr 14, 2025
470 days ago

CVE Severity & Scoring

Robotic Process Automation46 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local4 (8.7%)
Network34 (73.9%)
Unknown0 (0.0%)
Physical7 (15.2%)
Adjacent Network1 (2.2%)
Attack Complexity
Low43 (93.5%)
High3 (6.5%)
Unknown0 (0.0%)
User Interaction
None42 (91.3%)
Unknown0 (0.0%)
Required4 (8.7%)
Privileges Required
Low18 (39.1%)
High3 (6.5%)
None25 (54.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attac
May 12, 20229.831NONO
IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527.
Oct 6, 20239.830NONO
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM
Aug 22, 20239.827NONO
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.
Sep 29, 20227.525NONO
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288.
Aug 1, 20227.525NONO
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations.
Nov 3, 20227.524NONO
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-For
Aug 1, 20227.224NONO
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 2299
Aug 1, 20226.523NONO
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide
Jun 27, 20237.822NONO
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.
Oct 6, 20226.522NONO

Exploit Exposure

Signals from CVEs in this product scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (46 CVEs).

Media Mentions

Signals from CVEs in this product scope (46 CVEs).

Top CNAs Publishing CVEs For Robotic Process Automation

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23.0.919.80.6%00
23.0.119.80.6%00
23.0.028.20.5%00
21.0.417.50.7%00
21.0.326.00.5%00
21.0.266.30.6%00
21.0.1.215.41.0%00
21.0.166.20.7%00
21.0.036.90.8%00
20.12.516.50.7%00
20.10.016.50.7%00