CVE-2018-11060: High severity RSA Archer vulnerability
RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11060?
CVE-2018-11060 is a vulnerability in RSA Archer versions prior to 6.4.0.1 that allows a remote authenticated malicious user to bypass authorization and potentially elevate their privileges.
How severe is CVE-2018-11060?
CVE-2018-11060 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2018-11060?
RSA Archer versions prior to 6.4.0.1 are affected by CVE-2018-11060.
How can a malicious user exploit CVE-2018-11060?
A remote authenticated malicious Archer user can exploit CVE-2018-11060 to bypass authorization and potentially elevate their privileges.
Are there any references for CVE-2018-11060?
Yes, you can find references for CVE-2018-11060 at the following links: [http://seclists.org/fulldisclosure/2018/Jul/69](http://seclists.org/fulldisclosure/2018/Jul/69), [http://www.securityfocus.com/bid/104892](http://www.securityfocus.com/bid/104892), [http://www.securitytracker.com/id/1041359](http://www.securitytracker.com/id/1041359).