Rsa · Rsa Archer · CVE-2021-38362
**Name of the Vulnerable Software and Affected Versions**
RSA Archer versions 6.x through 6.9 SP3 (6.9.3.0)
**Description**
An authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
**Recommendations**
For RSA Archer versions 6.x through 6.9 SP3 (6.9.3.0), as a temporary workaround, consider restricting access to the vulnerable REST API endpoint until a patch is available.