PT-2020-18407 · Rsa · Rsa Archer

Published

2020-05-04

·

Updated

2020-05-11

·

CVE-2020-5332

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RSA Archer versions prior to 6.7 P3 (6.7.0.3)
Description The issue allows an authenticated malicious user with administrator privileges to potentially execute arbitrary commands on the system where the vulnerable application is deployed. This is achieved through a command injection vulnerability.
Recommendations For versions prior to 6.7 P3 (6.7.0.3), update to version 6.7 P3 (6.7.0.3) or later to resolve the issue. As a temporary workaround, consider restricting administrator privileges to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5332

Affected Products

Rsa Archer