Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.
2021-01-29T07:15:17.733
2024-11-21T05:24:10.180
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rsa | archer | < 6.6.0.8 | Yes |
Application | rsa | archer | < 6.7.0.8 | Yes |
Application | rsa | archer | < 6.8.0.5 | Yes |
Application | rsa | archer | < 6.9.0.1 | Yes |