First published: Mon May 04 2020(Updated: )
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | <6.7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5332 is a command injection vulnerability in RSA Archer versions prior to 6.7 P3 (6.7.0.3).
CVE-2020-5332 has a severity rating of critical with a CVSS score of 7.2.
CVE-2020-5332 affects RSA Archer versions prior to 6.7 P3 (6.7.0.3) and allows an authenticated malicious user with administrator privileges to execute arbitrary commands on the system.
To fix CVE-2020-5332, users should update RSA Archer to version 6.7 P3 (6.7.0.3) or later.
You can find more information about CVE-2020-5332 at this Dell support page: https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities