Those findings are expected when decompiling IBM RPA — the “hard-coded password” is an internal library constant (used for ZIP/crypto routines), not a real credential or customer secret. It’s not used for authentication or exposed externally.
The arithmetic and cipher suite points are implementation details of the runtime; they don’t indicate a security vulnerability in your deployment, but you should raise this with IBM Support for an official security statement if your auditors need documentation.