Lucene search

K
cveMitreCVE-2023-48641
HistoryDec 12, 2023 - 8:15 a.m.

CVE-2023-48641

2023-12-1208:15:07
CWE-639
mitre
web.nvd.nist.gov
15
cve-2023-48641
archer platform
vulnerability
security
nvd
authorization bypass

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

19.3%

Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.

Affected configurations

Nvd
Node
archerirmarcherRange<6.14.0.1.2
Node
archerirmarcherRange<6.13.0.3
VendorProductVersionCPE
archerirmarcher*cpe:2.3:a:archerirm:archer:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for CVE-2023-48641