CVE-2015-4543: Infoleak
EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4543?
CVE-2015-4543 has a medium severity rating as it allows unauthorized access to sensitive information stored in the database.
How do I fix CVE-2015-4543?
To mitigate CVE-2015-4543, upgrade your EMC RSA Archer GRC to version 5.5.3 or above where the issue is resolved.
What is the affected software for CVE-2015-4543?
CVE-2015-4543 affects EMC RSA Archer GRC versions 5.5.0, 5.5.1, and 5.5.2.
Can CVE-2015-4543 be exploited by remote users?
Yes, CVE-2015-4543 can be exploited by remote authenticated users who can read database fields containing cleartext passwords.
What type of vulnerability is CVE-2015-4543?
CVE-2015-4543 is classified as an information disclosure vulnerability due to the use of cleartext for stored passwords.