First published: Mon May 04 2020(Updated: )
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the privileges of the authenticated victim user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | <6.7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5335 is a cross-site request forgery vulnerability in RSA Archer versions prior to 6.7 P2 (6.7.0.2).
CVE-2020-5335 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2020-5335 by tricking a victim application user to send arbitrary requests to the vulnerable RSA Archer application.
Versions of RSA Archer prior to 6.7 P2 (6.7.0.2) are affected by CVE-2020-5335.
Yes, a security update is available for CVE-2020-5335. Please refer to the reference link for more information.