CVE-2014-4633: XSS
Published Dec 12, 2014
·Updated
Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
7 affected components
EMC Rsa Archer Egrc=5.0
EMC Rsa Archer Egrc=5.1
EMC Rsa Archer Egrc=5.2
EMC Rsa Archer Egrc=5.3
EMC Rsa Archer Egrc=5.4
EMC Rsa Archer Egrc=5.5
EMC Rsa Archer Egrc=5.5.1
Event History
Dec 12, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4633?
CVE-2014-4633 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-4633?
To fix CVE-2014-4633, update your EMC RSA Archer GRC Platform to version 5.5.1.1 or later.
3
What types of attacks does CVE-2014-4633 allow?
CVE-2014-4633 allows attackers to perform cross-site scripting, injecting arbitrary web scripts or HTML into the platform.
4
Which versions of EMC RSA Archer GRC Platform are affected by CVE-2014-4633?
CVE-2014-4633 affects EMC RSA Archer GRC Platform versions 5.0 to 5.5, excluding 5.5.1.1 and later.
5
What is the potential impact of CVE-2014-4633 on users?
The potential impact of CVE-2014-4633 includes session hijacking, data theft, or malicious actions executed on behalf of the user.