CVE-2014-0641: CSRF
Published Aug 20, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary users.
Affected Software
4 affected components
EMC Rsa Archer Egrc=5.3
EMC Rsa Archer Egrc=5.4
EMC Rsa Archer Egrc=5.4-sp1
EMC Rsa Archer Egrc=5.5
Event History
Aug 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0641?
CVE-2014-0641 is considered a high severity vulnerability due to its ability to allow remote attackers to hijack user authentication.
2
How do I fix CVE-2014-0641?
To fix CVE-2014-0641, upgrade to EMC RSA Archer GRC Platform version 5.5 SP1 or later.
3
Which versions are affected by CVE-2014-0641?
CVE-2014-0641 affects EMC RSA Archer GRC Platform versions 5.3, 5.4, and 5.4 SP1.
4
What type of vulnerability is CVE-2014-0641?
CVE-2014-0641 is a Cross-site Request Forgery (CSRF) vulnerability.
5
What could an attacker achieve with CVE-2014-0641?
An attacker exploiting CVE-2014-0641 could hijack the authentication of arbitrary users in the affected systems.