Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2024-07-26T13:52:28.961Z

Updated: 2024-08-01T21:45:38.274Z

Reserved: 2024-07-19T15:13:55.652Z

Link: CVE-2024-6922

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.274Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-26T14:15:03.377

Modified: 2024-07-29T14:12:08.783

Link: CVE-2024-6922

cve-icon Redhat

No data.