Описание
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.1.0.0 (включая) до 6.9.3.0.1 (исключая)
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.0026
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
EPSS
Процентиль: 49%
0.0026
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639