CVE-2022-26949
- EPSS 0.21%
- Veröffentlicht 30.03.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 06:54:51
Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra ...
CVE-2022-26948
- EPSS 0.26%
- Veröffentlicht 30.03.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 06:54:51
The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.
CVE-2022-26947
- EPSS 0.23%
- Veröffentlicht 30.03.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 06:54:51
Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript c...
CVE-2021-41594
- EPSS 0.25%
- Veröffentlicht 30.03.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:29
In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are r...
CVE-2021-29253
- EPSS 0.1%
- Veröffentlicht 26.05.2021 04:15:09
- Zuletzt bearbeitet 21.11.2024 06:00:53
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to...
CVE-2021-29252
- EPSS 0.26%
- Veröffentlicht 26.05.2021 04:15:09
- Zuletzt bearbeitet 21.11.2024 06:00:53
RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.
CVE-2020-29538
- EPSS 0.23%
- Veröffentlicht 29.01.2021 07:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:10
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this infor...
CVE-2020-29537
- EPSS 0.11%
- Veröffentlicht 29.01.2021 07:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:09
Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' crede...
CVE-2020-29536
- EPSS 0.07%
- Veröffentlicht 29.01.2021 07:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:09
Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.
CVE-2020-29535
- EPSS 0.22%
- Veröffentlicht 29.01.2021 07:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:09
Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When applica...