CVE-2018-15780: DSA-2018-224: RSA Archer GRC Platform Improper Access Control Vulnerability
Published Jan 3, 2019
·Updated
RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could potentially exploit this vulnerability to bypass authorization checks and gain read access to restricted user information.
Affected Software
1 affected component
RSA Archer GRC Platform<6.5.0.1
Event History
Jan 3, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-15780?
CVE-2018-15780 is an improper access control vulnerability in RSA Archer versions prior to 6.5.0.1.
2
How can a remote malicious user exploit CVE-2018-15780?
A remote malicious user can potentially exploit CVE-2018-15780 to bypass authorization checks and gain read access to restricted user information.
3
What is the severity of CVE-2018-15780?
CVE-2018-15780 has a severity level of medium (6.5).
4
Which version of RSA Archer is affected by CVE-2018-15780?
RSA Archer versions prior to 6.5.0.1 are affected by CVE-2018-15780.
5
How can I fix CVE-2018-15780?
To fix CVE-2018-15780, it is recommended to update to RSA Archer version 6.5.0.1 or later.