CVE-2019-3756: Infoleak
Published Sep 18, 2019
·Updated
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
Affected Software
1 affected component
RSA Archer<6.6.0.3
Event History
Sep 18, 2019
CVE Published
via MITRE·10:23 PM
Data Sourced
via MITRE·10:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-3756?
CVE-2019-3756 is an information disclosure vulnerability in RSA Archer versions prior to 6.6 P3 (6.6.0.3).
2
How does CVE-2019-3756 impact RSA Archer?
CVE-2019-3756 allows low-privileged RSA Archer users to access information from the backend database under certain error conditions.
3
What is the severity of CVE-2019-3756?
CVE-2019-3756 has a severity rating of 6.5 (medium).
4
How can I fix CVE-2019-3756?
To fix CVE-2019-3756, you should update RSA Archer to version 6.6 P3 (6.6.0.3) or later.
5
Where can I find more information about CVE-2019-3756?
You can find more information about CVE-2019-3756 at the following link: https://community.rsa.com/docs/DOC-106759