VendorsRSAarcher_grc_platformall versions
Vulnerabilities

RSA Archer GRC Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-3716
Information Exposure Vulnerability
Published 2019-03-13 · Modified
7.8EPSS 0.004
CVE-2019-3715
Information Exposure Vulnerability
Published 2019-03-13 · Modified
7.8EPSS 0.003
CVE-2018-15780
DSA-2018-224: RSA Archer GRC Platform Improper Access Control Vulnerability
Published 2019-01-03 · Modified
6.5EPSS 0.012
CVE-2017-14371
RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting via the request URL. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Published 2017-10-11 · Modified
6.1EPSS 0.011
CVE-2017-14372
RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Published 2017-10-11 · Modified
6.1EPSS 0.011
CVE-2017-14370
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Published 2017-10-11 · Modified
5.4EPSS 0.006
CVE-2017-14369
RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Archer user may potentially exploit this vulnerability to elevate their privileges and export certain application records.
Published 2017-10-11 · Modified
4.3EPSS 0.011