CVE-2021-41594

In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*

History

05 Apr 2022, 23:51

Type Values Removed Values Added
References (MISC) https://www.archerirm.community/t5/security-advisories/archer-an-rsa-business-update-for-multiple-vulnerabilities/ta-p/674497 - (MISC) https://www.archerirm.community/t5/security-advisories/archer-an-rsa-business-update-for-multiple-vulnerabilities/ta-p/674497 - Third Party Advisory
References (MISC) https://www.rsa.com/en-us/company/vulnerability-response-policy - (MISC) https://www.rsa.com/en-us/company/vulnerability-response-policy - Vendor Advisory
First Time Rsa
Rsa archer
CPE cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CWE NVD-CWE-noinfo

30 Mar 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-30 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-41594

Mitre link : CVE-2021-41594

CVE.ORG link : CVE-2021-41594


JSON object : View

Products Affected

rsa

  • archer