Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Troy Knutson

Researcher fromMandiant
#13041of 53,630
20.4Total CVSS
Vulnerabilities · 3
Medium
2
High
1
PT-2022-10271
8.5
2022-06-02
Rsa · Rsa Archer · CVE-2021-33615
**Name of the Vulnerable Software and Affected Versions** RSA Archer version 6.8.00500.1003 P5 **Description** The issue allows for the unrestricted upload of a file with a dangerous type. **Recommendations** For RSA Archer version 6.8.00500.1003 P5, consider restricting file upload capabilities to prevent the upload of dangerous file types until a patch is available.
PT-2022-10272
5.4
2022-04-04
Rsa · Rsa Archer · CVE-2021-33616
**Name of the Vulnerable Software and Affected Versions** RSA Archer versions 6.x through 6.9 SP1 P4 (6.9.1.4) **Description** The issue allows stored XSS. **Recommendations** For RSA Archer versions 6.x through 6.9 SP1 P4 (6.9.1.4), update to a version that contains a fix for this issue.
PT-2022-10714
6.5
2022-03-30
Rsa · Rsa Archer · CVE-2021-38362
**Name of the Vulnerable Software and Affected Versions** RSA Archer versions 6.x through 6.9 SP3 (6.9.3.0) **Description** An authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data. **Recommendations** For RSA Archer versions 6.x through 6.9 SP3 (6.9.3.0), as a temporary workaround, consider restricting access to the vulnerable REST API endpoint until a patch is available.