Cross-Site Request Forgery Vulnerability in RSA Archer by RSA Security
CVE-2020-5335

5MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
4 May 2020

Summary

RSA Archer, prior to version 6.7 P2 (6.7.0.2), is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw enables remote, unauthenticated attackers to exploit the vulnerability by tricking individuals with an authenticated session into sending unintended requests to the application. As a result, such requests would be executed with the user's privileges, potentially leading to unauthorized actions and data exposure within the RSA Archer environment.

Affected Version(s)

RSA Archer < 6.7 P2

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.