First published: Thu Aug 25 2022(Updated: )
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | >=6.0<6.10.0.4 | |
RSA Archer | >=6.11<6.11.0.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37317 refers to an HTML injection vulnerability in RSA Archer Platform 6.x before 6.11 P3.
CVE-2022-37317 affects RSA Archer Platform versions 6.x before 6.11 P3.
The severity rating of CVE-2022-37317 is high, with a CVSS score of 5.4.
An authenticated remote attacker can exploit CVE-2022-37317 by tricking a victim application user to execute malicious code in the context of the web application.
To mitigate the risk of CVE-2022-37317, it is recommended to update RSA Archer Platform to version 6.11 P3 or later.