[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] DSA-2018-038: RSA Archer GRC Platform Multiple Vulnerabilities
- To: "'fulldisclosure@xxxxxxxxxxxx'" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] DSA-2018-038: RSA Archer GRC Platform Multiple Vulnerabilities
- From: EMC Product Security Response Center <Security_Alert@xxxxxxx>
- Date: Mon, 5 Mar 2018 17:33:04 +0000
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
DSA-2018-038: RSA Archer GRC Platform Multiple Vulnerabilities
Dell EMC Identifier: DSA-2018-038
CVE Identifier: CVE-2018-1219, CVE-2018-1220
Severity: High
Severity Rating: CVSS v3 Base Score: See below for scores of individual CVEs
Affected Products:
RSA Archer versions prior to 6.2.0.8
Summary:
RSA Archer GRC 6.2.0.8 contains fixes for multiple security vulnerabilities
that could potentially be exploited by malicious users to compromise the
affected system.
Details:
RSA Archer product has been updated to address the following vulnerabilities:
Improper Access Control (CVE-2018-1219)
RSA Archer, versions prior to 6.2.0.8, contains an improper access control
vulnerability on an API which is used to enumerate user information. A remote
authenticated malicious user can potentially exploit this vulnerability to
gather information about the user base and may use this information in
subsequent attacks.
CVSSv3 Base Score: 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
URL Redirection to Untrusted Site (CVE-2018-1220)
RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the
QuickLinks feature. A remote attacker may potentially exploit this
vulnerability to redirect genuine users to phishing websites with the intent of
obtaining sensitive information from the users.
CVSSv3 Base Score: 8.3 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:
Recommendation:
The following RSA Archer release contains resolutions to these vulnerabilities:
RSA Archer version 6.2.0.8
RSA recommends all customers upgrade at the earliest opportunity.
Credit:
RSA would like to thank Erlend Leiknes, Security Consultant with Mnemonic AS
for reporting CVE-2018-1220.
For additional documentation, downloads, and more, visit the RSA Archer Suite
page on RSA Link.
Severity Rating:
For an explanation of Severity Ratings, refer to the RSA SecurID PASSCODE
Request knowledge base article. RSA recommends all customers take into account
both the base score and any relevant temporal and environmental scores which
may impact the potential severity associated with particular security
vulnerability.
EOPS Policy:
RSA has a defined End of Primary Support policy associated with all major
versions. Please refer to the Product Version Life Cycle for additional details.
RSA Link Security Advisories:
Read and use the information in this RSA Security Advisory to assist in
avoiding any situation that might arise from the problems described herein. If
you have any questions regarding this product alert, contact RSA Software
Technical Support at 1-800-995-5095. RSA Security LLC and its affiliates,
including without limitation, its ultimate parent company, Dell Technologies,
distribute RSA Security Advisories in order to bring to the attention of users
of the affected RSA products, important security information. RSA recommends
that all users determine the applicability of this information to their
individual situations and take appropriate action. The information set forth
herein is provided "as is" without warranty of any kind. RSA disclaims all
warranties, either express or implied, including the warranties of
merchantability, fitness for a particular purpose, title and non-infringement.
In no event shall RSA, its affiliates or its suppliers, be liable for any
damages whats
oever in
cluding direct, indirect, incidental, consequential, loss of business profits
or special damages, even if RSA, its affiliates or its suppliers have been
advised of the possibility of such damages. Some jurisdictions do not allow the
exclusion or limitation of liability for consequential or incidental damages,
so the foregoing limitation may not apply.
Dell EMC Product Security Response Center
security_alert@xxxxxxx
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEEazKDH3UU9DEtTDc5dty75+wTzVkFAlqdfkEACgkQdty75+wT
zVkonQf/YgR3WIwMY2UZRXTshGRAH+IuSwiaBW3BFzHk9rMzjKpfZqmT1kznq1Nh
6bvQFmyJvmLqqvCNYS8tiKUv4Kp52nzcKSsSX6A4i+KNFuJ7nHkq4hik/kZLoVqZ
k5fFgHsUuF35Hhil3t443jD1PfO2BglL3w/ZRJfiXt6xzC+TOQmNTcKBxlRHHTt5
XklwPR+5SK4PQf1l9JisFhl6Dob1BLWad49p62qaxS3VusyG1dEsnzl8WiBLxBbk
rodMW6ACU336CrYktIKzARG7IC9QoPX7DBZEpYZwcbOF0WX/yNLD9LpM9IN3IWTw
ZXJ+AzG+yMEPEMx5/Pofrc9XylPRPA==
=5AuT
-----END PGP SIGNATURE-----
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/