First published: Wed Oct 11 2017(Updated: )
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Questionnaire ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Archer | <=6.2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8016 is considered medium due to its potential for stored cross-site scripting attacks.
To fix CVE-2017-8016, upgrade the RSA Archer GRC Platform to version 6.2.0.5 or higher.
RSA Archer GRC Platform versions prior to 6.2.0.5 are vulnerable to CVE-2017-8016.
CVE-2017-8016 can facilitate stored cross-site scripting attacks allowing execution of arbitrary HTML in user sessions.
An authenticated attacker can exploit CVE-2017-8016 to execute arbitrary scripts in the context of the affected application.