URL Injection Vulnerability in RSA Archer by RSA Security
CVE-2020-5336

4.6MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
4 May 2020

Summary

RSA Archer prior to version 6.7 P1 (6.7.0.1) contains a URL injection vulnerability that can be exploited by an unauthenticated attacker. By deceiving a user of the application, the attacker may execute harmful JavaScript code within the affected system. This can lead to further attacks or unauthorized access, highlighting the importance of timely updates and monitoring for vulnerabilities in web applications.

Affected Version(s)

RSA Archer < 6.7 P1

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.