Rsa / Archer
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-37316 | Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present u… | MEDIUM | 6.5 | Aug 25, 2022 |
| CVE-2022-37318 | Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially ex… | HIGH | 7.0 | Aug 25, 2022 |
| CVE-2022-37317 | Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tr… | HIGH | 7.6 | Aug 25, 2022 |
| CVE-2021-33615 | RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. | HIGH | 7.5 | Jun 2, 2022 |
| CVE-2022-30584 | Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited… | CRITICAL | 9.6 | May 26, 2022 |
| CVE-2022-30585 | The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentia… | MEDIUM | 6.5 | May 26, 2022 |
| CVE-2021-33616 | RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. | MEDIUM | 5.4 | Apr 4, 2022 |
| CVE-2021-38362 | In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct O… | MEDIUM | 6.5 | Mar 30, 2022 |
| CVE-2021-41594 | In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2… | MEDIUM | 6.5 | Mar 29, 2022 |
| CVE-2022-26951 | Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this v… | MEDIUM | 6.5 | Mar 29, 2022 |
| CVE-2022-26950 | Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to… | MEDIUM | 6.1 | Mar 29, 2022 |
| CVE-2022-26949 | Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potential… | MEDIUM | 6.5 | Mar 29, 2022 |
| CVE-2022-26948 | The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may… | HIGH | 7.5 | Mar 29, 2022 |
| CVE-2022-26947 | Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulner… | MEDIUM | 6.3 | Mar 29, 2022 |
| CVE-2021-29253 | The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attac… | MEDIUM | 5.5 | May 26, 2021 |
| CVE-2021-29252 | RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields… | MEDIUM | 5.4 | May 26, 2021 |
| CVE-2020-29538 | Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentiall… | MEDIUM | 4.9 | Jan 29, 2021 |
| CVE-2020-29536 | Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain… | MEDIUM | 4.3 | Jan 29, 2021 |
| CVE-2020-29537 | Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitra… | MEDIUM | 5.4 | Jan 29, 2021 |
| CVE-2020-29535 | Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability t… | MEDIUM | 5.4 | Jan 29, 2021 |
| CVE-2020-26884 | RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability… | MEDIUM | 6.1 | Nov 18, 2020 |
| CVE-2020-5337 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulne… | MEDIUM | 6.1 | May 4, 2020 |
| CVE-2020-5336 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability… | MEDIUM | 6.1 | May 4, 2020 |
| CVE-2020-5335 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit… | HIGH | 8.8 | May 4, 2020 |
| CVE-2020-5334 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attac… | HIGH | 8.2 | May 4, 2020 |
Showing 1 to 25 of 33 CVEs