RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.
References
Link | Resource |
---|---|
https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities | Third Party Advisory |
Configurations
Information
Published : 2020-05-04 12:15
Updated : 2020-05-07 07:58
NVD link : CVE-2020-5336
Mitre link : CVE-2020-5336
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
rsa
- archer