EMC RSA Archer GRC Multiple Security Vulnerabilities
BID:103319
CVE-2018-1219 | CVE-2018-1220 |Info
EMC RSA Archer GRC Multiple Security Vulnerabilities
| Bugtraq ID: | 103319 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1219 CVE-2018-1220 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2018 12:00AM |
| Updated: | Mar 05 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
EMC RSA Archer GRC 5.5.2 EMC RSA Archer GRC 6.2.0.5 EMC RSA Archer GRC 6.2.0.2 EMC RSA Archer GRC 6.2 Patch 6 EMC RSA Archer GRC 5.5.3.4 EMC RSA Archer GRC 5.5.3.1 EMC RSA Archer GRC 5.5.2.3 EMC RSA Archer GRC 5.5.1.3.1 EMC RSA Archer GRC 5.5.1.1 EMC RSA Archer GRC 5.5 SP1 P3 EMC RSA Archer GRC 5.5 SP1 EMC RSA Archer GRC 5.5 EMC RSA Archer GRC 5.4.1.3 EMC RSA Archer GRC 5.4 SP1 P3 EMC RSA Archer GRC 5.4 SP1 P2 EMC RSA Archer GRC 5.4 SP1 P1 EMC RSA Archer GRC 5.4 SP1 EMC RSA Archer GRC 5.4 P2 EMC RSA Archer GRC 5.4 EMC RSA Archer GRC 5.3SP1 EMC RSA Archer GRC 5.3 EMC RSA Archer GRC 5.2SP1 EMC RSA Archer GRC 5.2 EMC RSA Archer GRC 5.0 |
| Not Vulnerable: |
EMC RSA Archer GRC 6.2.0.8 |
Discussion
EMC RSA Archer GRC Multiple Security Vulnerabilities
EMC RSA Archer GRC is prone to the following multiple security vulnerabilities:
1. An access-bypass Vulnerability.
2. An open-redirection Vulnerability.
Exploiting these issues will allow an attacker to bypass security restrictions or construct a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Versions prior to EMC RSA Archer GRC 6.2.0.8 are vulnerable.
EMC RSA Archer GRC is prone to the following multiple security vulnerabilities:
1. An access-bypass Vulnerability.
2. An open-redirection Vulnerability.
Exploiting these issues will allow an attacker to bypass security restrictions or construct a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Versions prior to EMC RSA Archer GRC 6.2.0.8 are vulnerable.
Exploit / POC
EMC RSA Archer GRC Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
EMC RSA Archer GRC Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC RSA Archer GRC Multiple Security Vulnerabilities
References:
References:
- DSA-2018-038: RSA Archer GRC Platform Multiple Vulnerabilities (seclists.org)
- EMC Homepage (EMC)