CVE-2017-14370: XSS
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14370?
CVE-2017-14370 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2017-14370?
To fix CVE-2017-14370, upgrade RSA Archer GRC Platform to version 6.2.0.5 or later.
What type of attack is possible with CVE-2017-14370?
CVE-2017-14370 allows for stored cross-site scripting attacks that can execute arbitrary HTML in the user's browser.
Who is affected by CVE-2017-14370?
All users of RSA Archer GRC Platform versions prior to 6.2.0.5 are affected by CVE-2017-14370.
What does CVE-2017-14370 exploit?
CVE-2017-14370 exploits the Source Asset ID field within the RSA Archer GRC Platform.