Back

MEDIUM

Server-Side Request Forgery in Automation 360

Published Jul 26, 2024

Description

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Jul 26, 2024
Updated Aug 1, 2024
Reserved Jul 19, 2024
CISA Vulnrichment
Updated Jul 26, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner rapid7
Published Jul 26, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-47909