EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
BID:62141
Info
EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
| Bugtraq ID: | 62141 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3277 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2013 12:00AM |
| Updated: | Sep 03 2013 12:00AM |
| Credit: | EMC |
| Vulnerable: |
EMC RSA Archer GRC 5.3SP1 EMC RSA Archer GRC 5.3 EMC RSA Archer GRC 5.2SP1 EMC RSA Archer GRC 5.2 |
| Not Vulnerable: |
EMC RSA Archer GRC 5.4 |
Discussion
EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
EMC RSA Archer GRC is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
EMC RSA Archer GRC versions prior to 5.4 are vulnerable.
EMC RSA Archer GRC is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
EMC RSA Archer GRC versions prior to 5.4 are vulnerable.
Exploit / POC
EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
Solution / Fix
EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC RSA Archer GRC CVE-2013-3277 Open Redirection Vulnerability
References:
References: