CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2022-30584

CVSS 9.6v3.1pub. 2022-05-26upd. 2024-11-21

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Rsa Archer

    APP
    Rsa
    6.3 – 6.9.3.4 (excl.)6.10.0.0 – 6.10.0.3 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-3758CRITICAL9.8PL ✓same product

RSA Archer — obejście uwierzytelnienia przez niewystarczające dane logowania

CVE-2022-37318HIGH7.0same product

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthent...

CVE-2022-37317HIGH7.6same product

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker c...

CVE-2021-33615HIGH7.5same product

RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

CVE-2020-5334HIGH8.2same product

RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site script...