CVE-2021-38362

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/03/2022
Last modified:
12/07/2022

Description

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:* 6.1.0.0 (including) 6.9.3.0.1 (excluding)