CVE-2022-37317: XSS
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37317?
CVE-2022-37317 refers to an HTML injection vulnerability in RSA Archer Platform 6.x before 6.11 P3.
How does CVE-2022-37317 affect RSA Archer Platform?
CVE-2022-37317 affects RSA Archer Platform versions 6.x before 6.11 P3.
What is the severity of CVE-2022-37317?
The severity rating of CVE-2022-37317 is high, with a CVSS score of 5.4.
How can an attacker exploit CVE-2022-37317?
An authenticated remote attacker can exploit CVE-2022-37317 by tricking a victim application user to execute malicious code in the context of the web application.
How can I mitigate the risk of CVE-2022-37317?
To mitigate the risk of CVE-2022-37317, it is recommended to update RSA Archer Platform to version 6.11 P3 or later.