Stored Cross-Site Scripting in RSA Archer by RSA Security
CVE-2018-11059

8.2HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
24 July 2018

Summary

RSA Archer, prior to version 6.4.0.1, is susceptible to a stored cross-site scripting vulnerability. This security issue allows an authenticated user to store malicious HTML or JavaScript code within the application's data store. When other users interact with the compromised data through their web browsers, the embedded malicious code executes, potentially compromising user sessions and data integrity. This vulnerability emphasizes the importance of ensuring security in web applications to protect against unauthorized exploitation.

Affected Version(s)

RSA Archer next of 6.4.0.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.