Vulnerability Description
RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Archer | >= 6.6, < 6.6.0.8 |
Related Weaknesses (CWE)
References
- https://community.rsa.com/t5/archer-product-advisories/rsa-2021-04-archer-an-rsaVendor Advisory
- https://www.rsa.com/en-us/company/vulnerability-response-policyVendor Advisory
- https://community.rsa.com/t5/archer-product-advisories/rsa-2021-04-archer-an-rsaVendor Advisory
- https://www.rsa.com/en-us/company/vulnerability-response-policyVendor Advisory
FAQ
What is CVE-2021-29252?
CVE-2021-29252 is a vulnerability with a CVSS score of 5.4 (MEDIUM). RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerabi...
How severe is CVE-2021-29252?
CVE-2021-29252 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29252?
Check the references section above for vendor advisories and patch information. Affected products include: Rsa Archer.