Lucene search

K

RSA Archer Security Vulnerabilities

cve
cve

CVE-2012-2294

EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to conduct clickjacking attacks via a crafted web...

6.8AI Score

0.003EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2012-2293

Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary code, via a relative...

7.1AI Score

0.002EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2012-2292

The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the Archer application, which allows remote attackers to bypass the Same Origin Policy via unspecified...

6.9AI Score

0.005EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2012-1064

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified...

5.9AI Score

0.001EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2013-0933

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allow remote attackers to inject arbitrary web script or HTML via unspecified...

5.9AI Score

0.001EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2013-0932

EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and upload arbitrary files via unspecified...

6.5AI Score

0.001EPSS

2022-10-03 04:15 PM
16
cve
cve

CVE-2013-0934

EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and modify global reports via unspecified...

6.4AI Score

0.001EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2013-3277

Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified...

6.9AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-3276

EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deactivated...

6.5AI Score

0.002EPSS

2022-10-03 04:14 PM
19
cve
cve

CVE-2020-5331

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further...

8.8CVSS

5.1AI Score

0.0004EPSS

2020-05-04 07:15 PM
31
cve
cve

CVE-2020-5336

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected...

6.1CVSS

6.6AI Score

0.001EPSS

2020-05-04 07:15 PM
31
cve
cve

CVE-2020-5333

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized...

4.3CVSS

4.3AI Score

0.001EPSS

2020-05-04 07:15 PM
25
cve
cve

CVE-2020-5334

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM...

8.2CVSS

6AI Score

0.001EPSS

2020-05-04 07:15 PM
26
cve
cve

CVE-2020-5335

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server...

8.8CVSS

8.6AI Score

0.002EPSS

2020-05-04 07:15 PM
26
cve
cve

CVE-2020-5332

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is...

7.2CVSS

7.4AI Score

0.002EPSS

2020-05-04 07:15 PM
27
cve
cve

CVE-2020-5337

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The...

6.1CVSS

6.2AI Score

0.001EPSS

2020-05-04 07:15 PM
23
cve
cve

CVE-2019-3758

RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those...

9.8CVSS

9.4AI Score

0.002EPSS

2019-09-18 11:15 PM
151
cve
cve

CVE-2019-3756

RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error...

6.5CVSS

6.2AI Score

0.001EPSS

2019-09-18 11:15 PM
149
cve
cve

CVE-2019-3716

RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further...

7.8CVSS

7.3AI Score

0.0004EPSS

2019-03-13 09:29 PM
44
cve
cve

CVE-2019-3715

RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further...

7.8CVSS

5.2AI Score

0.0004EPSS

2019-03-13 09:29 PM
44
cve
cve

CVE-2018-15780

RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could potentially exploit this vulnerability to bypass authorization checks and gain read access to restricted user...

6.5CVSS

6.4AI Score

0.001EPSS

2019-01-03 09:29 PM
46
cve
cve

CVE-2018-11065

The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to read...

4.3CVSS

5.3AI Score

0.001EPSS

2018-08-24 03:29 PM
52
cve
cve

CVE-2018-11060

RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their...

8.8CVSS

8.3AI Score

0.003EPSS

2018-07-24 07:29 PM
44
cve
cve

CVE-2018-11059

RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the...

8.2CVSS

4.9AI Score

0.001EPSS

2018-07-24 07:29 PM
46
cve
cve

CVE-2018-1220

EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtaining sensitive information from the...

6.1CVSS

6AI Score

0.001EPSS

2018-03-08 03:29 PM
23
cve
cve

CVE-2018-1219

EMC RSA Archer, versions prior to 6.2.0.8, contains an improper access control vulnerability on an API which is used to enumerate user information. A remote authenticated malicious user can potentially exploit this vulnerability to gather information about the user base and may use this...

4.3CVSS

4.7AI Score

0.001EPSS

2018-03-08 03:29 PM
20
cve
cve

CVE-2017-8025

RSA Archer GRC Platform prior to 6.2.0.5 is affected by an arbitrary file upload vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to upload malicious files via attachments to arbitrary paths on the web...

7.4CVSS

7.5AI Score

0.006EPSS

2017-10-11 07:29 PM
18
cve
cve

CVE-2017-8016

RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Questionnaire ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer...

5.4CVSS

5.9AI Score

0.0005EPSS

2017-10-11 07:29 PM
21
cve
cve

CVE-2017-14370

RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer...

5.4CVSS

5.9AI Score

0.0005EPSS

2017-10-11 07:29 PM
25
cve
cve

CVE-2017-14369

RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Archer user may potentially exploit this vulnerability to elevate their privileges and export certain application...

4.3CVSS

5.4AI Score

0.001EPSS

2017-10-11 07:29 PM
31
2
cve
cve

CVE-2017-14372

RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer...

6.1CVSS

6.4AI Score

0.001EPSS

2017-10-11 07:29 PM
25
cve
cve

CVE-2017-14371

RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting via the request URL. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer...

6.1CVSS

6.3AI Score

0.001EPSS

2017-10-11 07:29 PM
27
cve
cve

CVE-2017-4998

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is potentially affected by a cross-site request forgery vulnerability. A remote low privileged attacker may potentially exploit the vulnerability to execute unauthorized requests on behalf of the victim, using the authenticated...

8.8CVSS

8.5AI Score

0.002EPSS

2017-07-07 12:29 AM
22
cve
cve

CVE-2017-5000

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an information exposure through an error message vulnerability. A remote low privileged attacker may potentially exploit this vulnerability to use information disclosed in an error message to launch another more...

4.3CVSS

6.1AI Score

0.001EPSS

2017-07-07 12:29 AM
22
cve
cve

CVE-2017-4999

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an authorization bypass through user-controlled key vulnerability in Discussion Forum Messages. A remote low privileged attacker may potentially exploit this vulnerability to elevate their privileges and view other.....

6.5CVSS

7.4AI Score

0.001EPSS

2017-07-07 12:29 AM
21
cve
cve

CVE-2017-5001

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an information exposure through an error message vulnerability. A remote low privileged attacker may potentially exploit this vulnerability to use information disclosed in an error message to launch another more...

4.3CVSS

6.1AI Score

0.001EPSS

2017-07-07 12:29 AM
26
cve
cve

CVE-2017-5002

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials...

6.1CVSS

7.3AI Score

0.002EPSS

2017-07-07 12:29 AM
22
cve
cve

CVE-2017-4977

EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected...

7CVSS

6.4AI Score

0.001EPSS

2017-03-29 09:59 PM
21
cve
cve

CVE-2016-0899

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak...

6.3CVSS

6AI Score

0.001EPSS

2016-07-04 04:59 PM
20
cve
cve

CVE-2015-4543

EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database...

5.8AI Score

0.001EPSS

2015-09-26 01:59 AM
22
cve
cve

CVE-2015-4542

EMC RSA Archer GRC 5.x before 5.5.3 allows remote authenticated users to bypass intended access restrictions, and read or modify Discussion Forum Fields messages, via unspecified...

6.3AI Score

0.002EPSS

2015-09-26 01:59 AM
24
cve
cve

CVE-2015-4541

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2015-09-26 01:59 AM
15
cve
cve

CVE-2015-0542

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC RSA Archer GRC 5.5 SP1 before P3 allow remote attackers to hijack the authentication of arbitrary...

7.5AI Score

0.002EPSS

2015-08-20 10:59 AM
25
cve
cve

CVE-2014-4633

Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.001EPSS

2014-12-12 06:59 PM
15
cve
cve

CVE-2014-0640

EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on resource access via unspecified...

6.4AI Score

0.001EPSS

2014-08-20 11:17 AM
18
cve
cve

CVE-2014-2505

EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to trigger the download of arbitrary code, and consequently change the product's functionality, via unspecified...

7AI Score

0.006EPSS

2014-08-20 11:17 AM
18
cve
cve

CVE-2014-2517

Unspecified vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to gain privileges via unknown...

6.6AI Score

0.004EPSS

2014-08-20 11:17 AM
18
cve
cve

CVE-2014-0641

Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary...

7.4AI Score

0.002EPSS

2014-08-20 11:17 AM
20
cve
cve

CVE-2014-0639

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.4 SP1 P3 allow remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.002EPSS

2014-05-25 10:55 PM
17
cve
cve

CVE-2013-6178

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.4 SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.001EPSS

2013-12-19 10:55 PM
25