CRITICAL🇵🇱 Wersja polska

CVE-2019-3758

CVSS 9.8v3.1pub. 2019-09-18upd. 2024-11-21

RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Rsa Archer

    APP
    Rsa
    < 6.6.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-30584CRITICAL9.6PL ✓same product

RSA Archer – błąd kontroli dostępu w module SSO ADFS (RCE/przejęcie systemu)

CVE-2022-37317HIGH7.6same product

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker c...

CVE-2022-37318HIGH7.0same product

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthent...

CVE-2021-33615HIGH7.5same product

RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

CVE-2020-5331HIGH8.8same product

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session ...