CVE-2020-5331: Infoleak
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5331?
The severity of CVE-2020-5331 is high with a CVSS score of 5.5.
What is CVE-2020-5331?
CVE-2020-5331 is an information exposure vulnerability in RSA Archer versions prior to 6.7 P3 (6.7.0.3).
How can an attacker exploit CVE-2020-5331?
An authenticated malicious local user with access to the log files can exploit CVE-2020-5331 to obtain exposed session information.
What is the affected software for CVE-2020-5331?
RSA Archer versions prior to 6.7 P3 (6.7.0.3) are affected by CVE-2020-5331.
Is there a security update available for CVE-2020-5331?
Yes, a security update is available for CVE-2020-5331. Please refer to the reference link for more information.