Описание
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.4 (включая) до 6.6.0.8 (исключая)Версия от 6.7 (включая) до 6.7.0.8 (исключая)Версия от 6.8 (включая) до 6.8.0.5 (исключая)Версия от 6.9 (включая) до 6.9.0.2 (исключая)
Одно из
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.0005
Низкий
5.1 Medium
CVSS3
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-522
Связанные уязвимости
github
больше 3 лет назад
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.
EPSS
Процентиль: 15%
0.0005
Низкий
5.1 Medium
CVSS3
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-522