CVE-2012-2294: Input Validation
Published Feb 6, 2013
·Updated
EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to conduct clickjacking attacks via a crafted web page.
Affected Software
5 affected components
EMC RSA Archer SmartSuite=4.3
EMC RSA Archer SmartSuite=4.5
EMC Rsa Archer Egrc=5.0
EMC Rsa Archer Egrc=5.1
EMC Rsa Archer Egrc=5.2
Event History
Feb 6, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2294?
CVE-2012-2294 is considered a moderate severity vulnerability due to its potential for clickjacking attacks.
2
How do I fix CVE-2012-2294?
To fix CVE-2012-2294, upgrade to RSA Archer GRC version 5.2SP1 or later.
3
What software is affected by CVE-2012-2294?
CVE-2012-2294 affects EMC RSA Archer SmartSuite 4.x and RSA Archer GRC 5.x prior to version 5.2SP1.
4
What kind of attack does CVE-2012-2294 allow?
CVE-2012-2294 allows remote attackers to conduct clickjacking attacks via a crafted web page.
5
Is there a workaround for CVE-2012-2294 if I cannot upgrade?
There is no official workaround for CVE-2012-2294; upgrading is recommended as the primary mitigation.