CVE-2019-4297
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.4epss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.
CVSS:3.0/C:L/PR:L/AV:N/AC:L/I:L/UI:N/A:N/S:C/E:U/RL:O/RC:C
Affected products
IBM · Robotic Process Automation with Automation Anywhere