Cross-Site Request Forgery Vulnerability in RSA Archer by RSA Security
CVE-2020-5335
5MEDIUM
Summary
RSA Archer, prior to version 6.7 P2 (6.7.0.2), is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw enables remote, unauthenticated attackers to exploit the vulnerability by tricking individuals with an authenticated session into sending unintended requests to the application. As a result, such requests would be executed with the user's privileges, potentially leading to unauthorized actions and data exposure within the RSA Archer environment.
Affected Version(s)
RSA Archer < 6.7 P2
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved