CVE-2020-5335: CSRF
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the privileges of the authenticated victim user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5335?
CVE-2020-5335 is a cross-site request forgery vulnerability in RSA Archer versions prior to 6.7 P2 (6.7.0.2).
What is the severity of CVE-2020-5335?
CVE-2020-5335 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2020-5335?
An attacker can exploit CVE-2020-5335 by tricking a victim application user to send arbitrary requests to the vulnerable RSA Archer application.
Which versions of RSA Archer are affected by CVE-2020-5335?
Versions of RSA Archer prior to 6.7 P2 (6.7.0.2) are affected by CVE-2020-5335.
Is there a security update available for CVE-2020-5335?
Yes, a security update is available for CVE-2020-5335. Please refer to the reference link for more information.