Improper Access Control in Archer by RSA
CVE-2022-26949
5.3MEDIUM
Summary
Archer versions 6.x up to 6.9 SP2 P1 (6.9.2.1) are affected by an improper access control vulnerability concerning attachments. This vulnerability enables a remote authenticated malicious user to gain unauthorized access to files, which should only be accessible by users with elevated privileges. As a result, sensitive information may be exposed, highlighting the importance of applying security measures to safeguard affected systems.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved