CVE-2019-3715: Information Exposure Vulnerability
Published Mar 9, 2019
·Updated
RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.
Affected Software
2 affected components
RSA Archer GRC Platform<6.5
RSA Archer GRC Platform=6.5
Event History
Mar 13, 2019
CVE Published
09:29 PM
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-3715?
CVE-2019-3715 is an information exposure vulnerability in RSA Archer versions prior to 6.5 SP1.
2
What is the severity of CVE-2019-3715?
CVE-2019-3715 has a severity rating of 5.5 (high).
3
What is affected by CVE-2019-3715?
RSA Archer versions prior to 6.5 SP1 are affected by CVE-2019-3715.
4
How does CVE-2019-3715 work?
CVE-2019-3715 allows an authenticated malicious local user to obtain plain text session information from the RSA Archer log files.
5
How can I fix CVE-2019-3715?
To fix CVE-2019-3715, users should update to RSA Archer version 6.5 SP1 or later.