VYPR

RSA Archer

by Dell

CVEs (6)

  • CVE-2020-5331HigMay 4, 2020
    risk 0.57cvss 8.8epss 0.01

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to…

  • CVE-2020-5334HigMay 4, 2020
    risk 0.53cvss 8.2epss 0.01

    RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or…

  • CVE-2020-5332HigMay 4, 2020
    risk 0.47cvss 7.2epss 0.02

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is…

  • CVE-2020-5335MedMay 4, 2020
    risk 0.33cvss 5.0epss 0.00

    RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to…

  • CVE-2020-5337MedMay 4, 2020
    risk 0.30cvss 4.6epss 0.01

    RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously…

  • CVE-2020-5336MedMay 4, 2020
    risk 0.30cvss 4.6epss 0.01

    RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.