CVE-2022-37316
Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata to an authenticated user of the affected system. 6.10 P3 HF1 (6.10.0.3.1) is also a fixed release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37316?
The severity of CVE-2022-37316 is medium.
What is the vulnerability in Archer Platform 6.8 before 6.11 P3 (6.11.0.3)?
Archer Platform 6.8 before 6.11 P3 (6.11.0.3) has an improper API access control vulnerability in a multi-instance system.
How does the vulnerability in Archer Platform 6.8 before 6.11 P3 (6.11.0.3) affect the system?
The vulnerability could potentially present unauthorized metadata to an authenticated user of the affected system.
Which versions of RSA Archer are affected by CVE-2022-37316?
RSA Archer versions 6.8 to 6.10 P3 HF1 and 6.11 to 6.11 P3 are affected by CVE-2022-37316.
Is there a fix available for CVE-2022-37316?
Yes, RSA has released fixed versions 6.10 P3 HF1 (6.10.0.3.1) and 6.11 P3 (6.11.0.3) to address the vulnerability.