CVE-2018-1547
HIGHIBM Robotic Process Automation with Automation Anywhere 10.0 - RCE
Title source: llmDescription
IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104469
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/142651
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22016197
Scores
CVSS v3
8.0
EPSS
0.0218
EPSS Percentile
80.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
Status
published
Products (1)
ibm/robotic_process_automation_with_automation_anywhere
10.0
Published
Jun 07, 2018
Tracked Since
Feb 18, 2026