Information disclosure in RSA Archer - CVE-2017-5000
Published: July 4, 2017
Vulnerability identifier: #VU7314
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper input validation. A remote attacker can send specially crafted data and gain access to potentially sensitive information from an error message.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
RSA Archer
How to mitigate CVE-2017-5000
Update to version 6.2.0.2.