CVE-2024-51456
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-780
- Published
- 2025-01-12
- Last modified
- 2026-03-13
Affected products
- IBM Robotic Process Automation
- IBM Robotic Process Automation
Weakness type
Related vulnerabilities
- CVE-2025-9071 — Insecure RSA-OAEP implementation with all-zero seed for padding in Oberon PSA Crypto
- CVE-2022-40722 — Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.