Lucene search

K
cvelistMitreCVELIST:CVE-2021-41594
HistoryMar 29, 2022 - 11:33 p.m.

CVE-2021-41594

2022-03-2923:33:34
mitre
www.cve.org
4
rsa archer 6.9
api endpoint
unauthorized access

EPSS

0.001

Percentile

28.4%

In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.

EPSS

0.001

Percentile

28.4%

Related for CVELIST:CVE-2021-41594