Lucene search

K
nvd[email protected]NVD:CVE-2023-48641
HistoryDec 12, 2023 - 8:15 a.m.

CVE-2023-48641

2023-12-1208:15:07
CWE-639
web.nvd.nist.gov
3
archer platform 6.x
6.14 p1 hf2
insecure direct object reference
multi-instance installation
exploit vulnerability
bypass authorization checks
awf application resources

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%

Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.

Affected configurations

Nvd
Node
archerirmarcherRange<6.14.0.1.2
Node
archerirmarcherRange<6.13.0.3
VendorProductVersionCPE
archerirmarcher*cpe:2.3:a:archerirm:archer:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%

Related for NVD:CVE-2023-48641