Medium
CVE-2022-43900 CVSS:5.3
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system.
CVE-2022-43901 CVSS:5.7
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components
IBM
Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.