First published: Wed Oct 11 2017(Updated: )
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | <=6.2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14370 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
To fix CVE-2017-14370, upgrade RSA Archer GRC Platform to version 6.2.0.5 or later.
CVE-2017-14370 allows for stored cross-site scripting attacks that can execute arbitrary HTML in the user's browser.
All users of RSA Archer GRC Platform versions prior to 6.2.0.5 are affected by CVE-2017-14370.
CVE-2017-14370 exploits the Source Asset ID field within the RSA Archer GRC Platform.