CVE-2022-37318: XSS
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37318?
CVE-2022-37318 is a reflected XSS vulnerability in RSA Archer Platform version 6.9 SP2 P2 before 6.11 P3 (6.11.0.3).
How does CVE-2022-37318 work?
CVE-2022-37318 allows a remote unauthenticated malicious Archer user to exploit the vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application.
What is the severity of CVE-2022-37318?
The severity of CVE-2022-37318 is high with a CVSS score of 6.1.
Which software versions are affected by CVE-2022-37318?
RSA Archer Platform versions 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) and 6.11.0.2.4 are affected by CVE-2022-37318.
How can I fix CVE-2022-37318?
To fix CVE-2022-37318, update your RSA Archer Platform to version 6.11 P3 (6.11.0.3) or later.