DSA-2018-224: RSA Archer GRC Platform Improper Access Control Vulnerability
CVE-2018-15780

4.3MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
3 January 2019

Summary

RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could potentially exploit this vulnerability to bypass authorization checks and gain read access to restricted user information.

Affected Version(s)

RSA Archer < 6.5.0.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RSA would like to thank Sam Sayen for reporting this vulnerability.
.