CVE-2020-26884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
18/11/2020
Last modified:
01/12/2020

Description

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:* 6.8 (including) 6.8.0.3 (including)
cpe:2.3:a:rsa:archer:6.9:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools