CVE-2018-1547

HIGH

IBM Robotic Process Automation with Automation Anywhere 10.0 - RCE

Title source: llm
STIX 2.1

Description

IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104469
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/142651
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22016197

Scores

CVSS v3 8.0
EPSS 0.0218
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

Status published
Products (1)
ibm/robotic_process_automation_with_automation_anywhere 10.0
Published Jun 07, 2018
Tracked Since Feb 18, 2026