CVE-2020-5332: OS Command Injection
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5332?
CVE-2020-5332 is a command injection vulnerability in RSA Archer versions prior to 6.7 P3 (6.7.0.3).
What is the severity of CVE-2020-5332?
CVE-2020-5332 has a severity rating of critical with a CVSS score of 7.2.
How does CVE-2020-5332 affect RSA Archer?
CVE-2020-5332 affects RSA Archer versions prior to 6.7 P3 (6.7.0.3) and allows an authenticated malicious user with administrator privileges to execute arbitrary commands on the system.
How can I fix CVE-2020-5332?
To fix CVE-2020-5332, users should update RSA Archer to version 6.7 P3 (6.7.0.3) or later.
Where can I find more information about CVE-2020-5332?
You can find more information about CVE-2020-5332 at this Dell support page: https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities