Rsa archer
This hub aggregates every CVE we track for Rsa archer, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH7LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Rsa archer.
- CVE-2020-5337RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users...4.6
- CVE-2020-5335RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a vict...5.0
- CVE-2020-5336RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user...4.6
- CVE-2020-5334RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vul...8.2
- CVE-2020-5331RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malic...8.8
- CVE-2020-5333RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerabil...4.3
- CVE-2020-5332RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability...7.2
- CVE-2019-3756RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI u...6.5
- CVE-2019-3758RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthent...9.8
- CVE-2019-3715Information Exposure Vulnerability7.8
- CVE-2019-3716Information Exposure Vulnerability7.8
- CVE-2018-15780DSA-2018-224: RSA Archer GRC Platform Improper Access Control Vulnerability4.3
- CVE-2018-11065The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user coul...2.7
- CVE-2018-11060RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to el...8.8
- CVE-2018-11059RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malici...8.2
Product normalization is registry-driven with AI assist and human review. How it works