First published: Tue May 07 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Archer | =5.0 | |
EMC RSA Archer | =5.1 | |
EMC RSA Archer | =5.2 | |
EMC RSA Archer | =5.3 | |
EMC RSA Archer | =4.3 | |
EMC RSA Archer | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0933 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-0933, upgrade EMC RSA Archer to version 5.3SP1 or later.
CVE-2013-0933 affects EMC RSA Archer versions 5.0 through 5.3 and Archer Smart Suite Framework versions 4.x.
Yes, CVE-2013-0933 can be exploited remotely by attackers to inject arbitrary web scripts.
Common mitigation strategies for CVE-2013-0933 include input validation and using web application firewalls.