Information Exposure Vulnerability in RSA Archer by RSA Security
CVE-2020-5331
8.8HIGH
Summary
RSA Archer software prior to version 6.7 P3 (6.7.0.3) contains a vulnerability that allows information exposure through improper handling of session data. This can lead to sensitive user session information being inadvertently cached or logged. An authenticated local user who gains access to these logs may retrieve this sensitive information, potentially enabling further malicious activities.
Affected Version(s)
RSA Archer < 6.7 P3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved