Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf9w-rf5f-3wcr

Опубликовано: 01 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

EPSS

Процентиль: 49%
0.0026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

EPSS

Процентиль: 49%
0.0026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863