CVE-2021-38362: Medium severity rsa archer grc platform vulnerability
Published Mar 30, 2022
·Updated
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
Affected Software
1 affected component
RSA Archer>=6.1.0.0<6.9.3.0.1
Event History
Mar 30, 2022
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-38362.
2
What is the severity rating of CVE-2021-38362?
CVE-2021-38362 has a severity rating of 6.5 (medium).
3
What software versions are affected by CVE-2021-38362?
CVE-2021-38362 affects RSA Archer 6.x through 6.9 SP3 (6.9.3.0).
4
What is the CWE category of CVE-2021-38362?
CVE-2021-38362 belongs to CWE category 639.
5
How can an attacker exploit CVE-2021-38362?
An authenticated attacker can make a GET request to a vulnerable REST API endpoint in RSA Archer and retrieve sensitive data.