CVE-2020-29537
Last modified
CVE-2020-29537 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Archer | >= 6.6, < 6.6.0.8 |
| Rsa | Archer | >= 6.7, < 6.7.0.8 |
| Rsa | Archer | >= 6.8, < 6.8.0.2 |
References
- https://community.rsa.com/docs/DOC-115223Vendor Advisory
- https://community.rsa.com/docs/DOC-115223Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-29537?
How severe is CVE-2020-29537?
How do I fix CVE-2020-29537?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2952Vulnerability in the Oracle HTTP Server product of Oracle Fu…6.5
- CVE-2020-29529HashiCorp go-slug up to 0.4.3 did not fully protect against …7.5
- CVE-2020-2953Vulnerability in the Oracle Retail Customer Management and S…9.8
- CVE-2020-29534An issue was discovered in the Linux kernel before 5.9.3. io…7.8
- CVE-2020-29535Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnera…5.4
- CVE-2020-29536Archer before 6.8 P2 (6.8.0.2) is affected by a path exposur…4.3
- CVE-2020-29538Archer before 6.9 P1 (6.9.0.1) contains an improper access c…4.9
- CVE-2020-29539A Cross-Site Scripting (XSS) issue in WebUI Translation in S…5.4
- CVE-2020-2954Vulnerability in the PeopleSoft Enterprise HRMS product of O…6.1
- CVE-2020-29540API calls in the Translation API feature in Systran Pure Neu…7.5
- CVE-2020-29547An issue was discovered in Citadel through webcit-926. Meddl…5.9
- CVE-2020-29548An issue was discovered in SmarterTools SmarterMail through …8.1
Are you affected by CVE-2020-29537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
