PT-2021-11688 · Rsa · Archery

Published

2021-01-29

·

Updated

2021-02-03

·

CVE-2020-29537

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Archer versions prior to 6.8 P2 (6.8.0.2)
Description: The issue allows a remote privileged attacker to potentially redirect legitimate users to arbitrary web sites, facilitating phishing attacks. This could lead to the theft of victims' credentials, enabling silent authentication to the Archer application without the victims' knowledge.
Recommendations: For versions prior to 6.8 P2 (6.8.0.2), update to version 6.8 P2 (6.8.0.2) or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive features that may be exploited through the open redirect vulnerability.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29537

Affected Products

Archery