CVE-2020-5337: Medium severity rsa archer grc platform vulnerability
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5337?
CVE-2020-5337 is a URL redirection vulnerability in RSA Archer versions prior to 6.7 P1 (6.7.0.1).
How does CVE-2020-5337 affect RSA Archer?
CVE-2020-5337 affects RSA Archer versions prior to 6.7 P1 (6.7.0.1).
What is the severity of CVE-2020-5337?
The severity of CVE-2020-5337 is medium with a CVSSv3 score of 6.1.
How can an attacker exploit CVE-2020-5337?
An attacker can exploit CVE-2020-5337 by tricking RSA Archer application users to click on maliciously crafted links and redirecting them to arbitrary web URLs.
Is there a security update available for CVE-2020-5337?
Yes, RSA Archer has released a security update to address CVE-2020-5337. Please refer to the following reference for more information: [RSA Archer Security Update for Multiple Vulnerabilities](https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities).