VulnerabilityModified
CVE-2016-0899
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.
MEDIUM 6.3EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- emc/rsa archer egrc
- Source
- security_alert@emc.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.