cbcvebase.

Rsa Archer vulnerabilities

33 known vulnerabilities affecting rsa/archer.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM26

Vulnerabilities

Page 2 of 2
CVE-2022-26951P4MEDIUMCVSS 6.1≥ 6.1.0.0, < 6.10.0.12022-03-30
CVE-2022-26951 [MEDIUM] CWE-79 CVE-2022-26951: Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthentic Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim an
nvd
CVE-2022-26950P4MEDIUMCVSS 6.1≥ 6.1.0.0, < 6.9.0.32022-03-30
CVE-2022-26950 [MEDIUM] CWE-601 CVE-2022-26950: Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivil Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing
nvd
CVE-2022-37318P4MEDIUMCVSS 6.1≥ 6.9.2.2, < 6.10.0.4≥ 6.11, < 6.11.0.2.42022-08-25
CVE-2022-37318 [MEDIUM] CWE-79 CVE-2022-37318: Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets exe
nvd
CVE-2021-33616P4MEDIUMCVSS 5.4≥ 6.1.0.0, ≤ 6.9.1.42022-04-04
CVE-2021-33616 [MEDIUM] CWE-79 CVE-2021-33616: RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
nvd
CVE-2018-11059P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.1.0.3≥ 6.2.0.0, < 6.2.0.10+2 more2018-07-24
CVE-2018-11059 [MEDIUM] CWE-79 CVE-2018-11059: RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicio
nvd
CVE-2020-29535P4MEDIUMCVSS 5.4≥ 6.6, < 6.6.0.8≥ 6.7, < 6.7.0.8+2 more2021-01-29
CVE-2020-29535 [MEDIUM] CWE-79 CVE-2020-29535: Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by
nvd
CVE-2020-29537P4MEDIUMCVSS 5.4≥ 6.6, < 6.6.0.8≥ 6.7, < 6.7.0.8+1 more2021-01-29
CVE-2020-29537 [MEDIUM] CWE-601 CVE-2020-29537: Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged at Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an atta
nvd
CVE-2021-29253P4MEDIUMCVSS 5.5≥ 6.4, < 6.6.0.8≥ 6.7, < 6.7.0.8+2 more2021-05-26
CVE-2021-29253 [MEDIUM] CWE-522 CVE-2021-29253: The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an in The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.
nvd
CVE-2020-29538P4MEDIUMCVSS 4.9≥ 6.6, < 6.6.0.8≥ 6.7, < 6.7.0.8+2 more2021-01-29
CVE-2020-29538 [MEDIUM] CVE-2020-29538: Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.
nvd
CVE-2020-5331P4MEDIUMCVSS 5.5fixed in 6.7.0.32020-05-04
CVE-2020-5331 [MEDIUM] CWE-598 CVE-2020-5331: RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.
nvd
CVE-2022-26947P4MEDIUMCVSS 5.4≥ 6.1.0.0, < 6.9.3.12022-03-30
CVE-2022-26947 [MEDIUM] CWE-79 CVE-2022-26947: Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets
nvd
CVE-2020-5333P4MEDIUMCVSS 4.3fixed in 6.7.0.32020-05-04
CVE-2020-5333 [MEDIUM] CWE-285 CVE-2020-5333: RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.
nvd
CVE-2020-29536P4MEDIUMCVSS 4.3≥ 6.6, < 6.6.0.8≥ 6.7, < 6.7.0.8+1 more2021-01-29
CVE-2020-29536 [MEDIUM] CWE-327 CVE-2020-29536: Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.
nvd
Rsa Archer vulnerabilities | cvebase