PT-2022-18135 · Rsa · Archery

Published

2022-03-29

·

Updated

2023-08-08

·

CVE-2022-26949

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Archer versions 6.x through 6.9 SP2 P1 (6.9.2.1)
Description The issue is related to improper access control on attachments, allowing a remote authenticated malicious user to potentially gain access to files that should only be allowed by extra privileges.
Recommendations For versions 6.x through 6.9 SP2 P1 (6.9.2.1), consider restricting access to attachments to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the privileges of remote authenticated users to prevent them from accessing sensitive files.

Fix

Related Identifiers

CVE-2022-26949

Affected Products

Archery