PT-2021-11689 · Rsa · Archery

Published

2021-01-29

·

Updated

2021-07-21

·

CVE-2020-29538

CVSS v3.1

4.9

Medium

VectorAC:L/AV:N/A:N/C:N/I:H/PR:H/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: Archer versions prior to 6.9 P1 (6.9.0.1)
Description: The issue is related to improper access control in an API, allowing a remote authenticated malicious administrative user to gather system information, which could be used in subsequent attacks.
Recommendations: For versions prior to 6.9 P1 (6.9.0.1), update to version 6.9 P1 (6.9.0.1) or later to resolve the issue. As a temporary workaround, consider restricting access to the API to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-29538

Affected Products

Archery