CVE-2020-5336: XSS
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5336?
CVE-2020-5336 is a URL injection vulnerability in RSA Archer versions prior to 6.7 P1 (6.7.0.1).
How can an attacker exploit CVE-2020-5336?
An unauthenticated attacker could exploit CVE-2020-5336 by tricking a victim application user to execute malicious JavaScript code on the affected system.
What is the severity of CVE-2020-5336?
CVE-2020-5336 has a severity rating of medium (6.1).
Is there a fix for CVE-2020-5336?
Yes, updating RSA Archer to version 6.7 P1 (6.7.0.1) or later will fix CVE-2020-5336.
Where can I find more information about CVE-2020-5336?
You can find more information about CVE-2020-5336 at the following reference: [RSA Archer Security Update for Multiple Vulnerabilities](https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities).