First published: Wed Sep 18 2019(Updated: )
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | <6.6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3756 is an information disclosure vulnerability in RSA Archer versions prior to 6.6 P3 (6.6.0.3).
CVE-2019-3756 allows low-privileged RSA Archer users to access information from the backend database under certain error conditions.
CVE-2019-3756 has a severity rating of 6.5 (medium).
To fix CVE-2019-3756, you should update RSA Archer to version 6.6 P3 (6.6.0.3) or later.
You can find more information about CVE-2019-3756 at the following link: https://community.rsa.com/docs/DOC-106759