RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is then executed by the web browser in the context of the vulnerable web application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:LRsa Archer
APPRsa< 6.7.0.2
Related vulnerabilities
RSA Archer – błąd kontroli dostępu w module SSO ADFS (RCE/przejęcie systemu)
RSA Archer — obejście uwierzytelnienia przez niewystarczające dane logowania
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthent...
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker c...
RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.