CVE-2017-14371: XSS
RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting via the request URL. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14371?
CVE-2017-14371 has a medium severity rating due to its ability to allow reflected cross-site scripting attacks.
How do I fix CVE-2017-14371?
To fix CVE-2017-14371, upgrade to RSA Archer GRC Platform version 6.2.0.5 or later.
What types of attack does CVE-2017-14371 allow?
CVE-2017-14371 allows attackers to execute arbitrary HTML and JavaScript code in a user's browser session.
Which versions of RSA Archer GRC Platform are vulnerable to CVE-2017-14371?
Versions prior to 6.2.0.5 of RSA Archer GRC Platform are vulnerable to CVE-2017-14371.
Who might be affected by CVE-2017-14371?
Users of RSA Archer GRC Platform prior to version 6.2.0.5 are at risk of exploitation via CVE-2017-14371.