VulnerabilityModified
CVE-2017-14372
RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages.
MEDIUM 6.1EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- rsa/archer grc platform
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2017/Oct/12Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101195Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039518Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Oct/12Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101195Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039518Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.