VulnerabilityModified
CVE-2017-14370
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field.
MEDIUM 5.4EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- rsa/archer grc platform
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2017/Oct/12Mailing List, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039518Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Oct/12Mailing List, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039518Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.