PT-2022-11436 · Rsa · Rsa Archer

Published

2022-03-29

·

Updated

2022-04-06

·

CVE-2021-41594

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RSA Archer version 6.9.SP1 P3
Description The issue allows an attacker to bypass precluded application functions by intercepting the API request at the "/api/V2/internal/TaskPermissions/CheckTaskAccess" endpoint. If the parameters of this request are replaced with empty fields, the attacker can achieve access to the precluded functions.
Recommendations For RSA Archer version 6.9.SP1 P3, as a temporary workaround, consider restricting access to the "/api/V2/internal/TaskPermissions/CheckTaskAccess" endpoint until a patch is available. Additionally, ensure that all API requests are properly validated to prevent parameter manipulation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-41594

Affected Products

Rsa Archer