CVE-2022-26949
- EPSS 0.21%
- Published 30.03.2022 00:15:09
- Last modified 21.11.2024 06:54:51
Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra ...
CVE-2022-26948
- EPSS 0.26%
- Published 30.03.2022 00:15:09
- Last modified 21.11.2024 06:54:51
The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.
CVE-2022-26947
- EPSS 0.23%
- Published 30.03.2022 00:15:09
- Last modified 21.11.2024 06:54:51
Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript c...
CVE-2021-41594
- EPSS 0.25%
- Published 30.03.2022 00:15:08
- Last modified 21.11.2024 06:26:29
In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are r...
CVE-2021-29253
- EPSS 0.1%
- Published 26.05.2021 04:15:09
- Last modified 21.11.2024 06:00:53
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to...
CVE-2021-29252
- EPSS 0.26%
- Published 26.05.2021 04:15:09
- Last modified 21.11.2024 06:00:53
RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.
CVE-2020-29538
- EPSS 0.23%
- Published 29.01.2021 07:15:17
- Last modified 21.11.2024 05:24:10
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this infor...
CVE-2020-29537
- EPSS 0.11%
- Published 29.01.2021 07:15:17
- Last modified 21.11.2024 05:24:09
Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' crede...
CVE-2020-29536
- EPSS 0.07%
- Published 29.01.2021 07:15:17
- Last modified 21.11.2024 05:24:09
Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.
CVE-2020-29535
- EPSS 0.22%
- Published 29.01.2021 07:15:17
- Last modified 21.11.2024 05:24:09
Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When applica...