Information disclosure in RSA Archer - CVE-2017-5000

 

Information disclosure in RSA Archer - CVE-2017-5000

Published: July 4, 2017


Vulnerability identifier: #VU7314
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged attacker to obtain potentially sensitive information on the target system.

The weakness exists due to improper input validation. A remote attacker can send specially crafted data and gain access to potentially sensitive information from an error message.

Successful exploitation of the vulnerability results in information disclosure.


Affected software

RSA Archer

How to mitigate CVE-2017-5000

Update to version 6.2.0.2.


External References

Related Security Bulletins