PT-2021-11688 · Rsa · Archery
Published
2021-01-29
·
Updated
2021-02-03
·
CVE-2020-29537
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Archer versions prior to 6.8 P2 (6.8.0.2)
Description:
The issue allows a remote privileged attacker to potentially redirect legitimate users to arbitrary web sites, facilitating phishing attacks. This could lead to the theft of victims' credentials, enabling silent authentication to the Archer application without the victims' knowledge.
Recommendations:
For versions prior to 6.8 P2 (6.8.0.2), update to version 6.8 P2 (6.8.0.2) or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive features that may be exploited through the open redirect vulnerability.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archery