Skip to main content

Vendor/product archive

rsa / archer CVEs

Beta · best-effort

33 CVEs tagged to rsa / archer2 Critical, 8 High, 22 Medium, 1 Low, 0 Unrated.

CVE-2022-37318

Published Aug 25, 2022

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerabi…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37317

Published Aug 25, 2022

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim appl…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37316

Published Aug 25, 2022

Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33615

Published Jun 2, 2022

RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30585

Published May 26, 2022

The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vul…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30584

Published May 26, 2022

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users t…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33616

Published Apr 4, 2022

RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38362

Published Mar 30, 2022

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDO…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26951

Published Mar 30, 2022

Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tric…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26950

Published Mar 30, 2022

Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26949

Published Mar 30, 2022

Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vuln…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26948

Published Mar 30, 2022

The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to cre…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26947

Published Mar 30, 2022

Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41594

Published Mar 30, 2022

In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermis…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29253

Published May 26, 2021

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to t…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29252

Published May 26, 2021

RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially e…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29538

Published Jan 29, 2021

Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulne…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29537

Published Jan 29, 2021

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and con…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29536

Published Jan 29, 2021

Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive informatio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29535

Published Jan 29, 2021

Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HT…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26884

Published Nov 18, 2020

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5337

Published May 4, 2020

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5336

Published May 4, 2020

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5335

Published May 4, 2020

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5334

Published May 4, 2020

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentiall…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2