First published: Mon Jun 18 2018(Updated: )
RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | >=6.1.0.0<6.1.0.3 | |
RSA Archer | >=6.2.0.0<6.2.0.10 | |
RSA Archer | >=6.3.0.0<6.3.0.7 | |
RSA Archer | =6.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11060 is a vulnerability in RSA Archer versions prior to 6.4.0.1 that allows a remote authenticated malicious user to bypass authorization and potentially elevate their privileges.
CVE-2018-11060 has a severity score of 8.8, which is considered high.
RSA Archer versions prior to 6.4.0.1 are affected by CVE-2018-11060.
A remote authenticated malicious Archer user can exploit CVE-2018-11060 to bypass authorization and potentially elevate their privileges.
Yes, you can find references for CVE-2018-11060 at the following links: [http://seclists.org/fulldisclosure/2018/Jul/69](http://seclists.org/fulldisclosure/2018/Jul/69), [http://www.securityfocus.com/bid/104892](http://www.securityfocus.com/bid/104892), [http://www.securitytracker.com/id/1041359](http://www.securitytracker.com/id/1041359).