
CVE-2020-5333
https://notcve.org/view.php?id=CVE-2020-5333
04 May 2020 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information. RSA Archer, versiones anteriores a la versión 6.7 P3 (6.7.0.3), contienen una vulnerabilidad de omisión de autorización en la API REST. Un usuario de Archer malicioso autenticado remoto podría explotar potencialmente esta vulnerabilidad para visualizar información no autorizad... • https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities • CWE-285: Improper Authorization CWE-863: Incorrect Authorization •

CVE-2020-5332
https://notcve.org/view.php?id=CVE-2020-5332
04 May 2020 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed. RSA Archer, versiones anteriores a la versión 6.7 P3 (6.7.0.3), contienen una vulnerabilidad de inyección de comandos. Un usuario malicioso autenticado con privilegios de administrador podría explotar potencialmente esta vul... • https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2020-5331
https://notcve.org/view.php?id=CVE-2020-5331
04 May 2020 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks. RSA Archer, versiones anteriores a la versión 6.7 P3 (6.7.0.3), contienen una vulnerabilidad de exposición de información. La información de sesión de los usuarios podría ser almacenada potencialmente en la ... • https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-598: Use of GET Request Method With Sensitive Query Strings •

CVE-2019-18574
https://notcve.org/view.php?id=CVE-2019-18574
03 Dec 2019 — RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser. El software RSA Authentication Manager versiones ... • https://www.dell.com/support/security/en-us/details/DOC-109297/DSA-2019-168-RSA®%3B-Authentication-Manager-Software-Stored-Cross-Site-Scripting-Vulnerability • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-3758
https://notcve.org/view.php?id=CVE-2019-3758
18 Sep 2019 — RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts. RSA Archer, versiones anteriores a 6.6 P2 (6.6.0.2), contienen una vulnerabilidad de autenticación inapropiada. La vulnerabilidad permite a los administradores de sistema crear cuentas de usuario con credenciales insuficientes. • https://community.rsa.com/docs/DOC-106759 • CWE-288: Authentication Bypass Using an Alternate Path or Channel CWE-521: Weak Password Requirements •

CVE-2019-3756
https://notcve.org/view.php?id=CVE-2019-3756
18 Sep 2019 — RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions. RSA Archer, versiones anteriores a 6.6 P3 (6.6.0.3), contienen una vulnerabilidad de divulgación de información. La información relacionada con la base de datos del backend es divulgada en la IU de usuarios de RSA Archer poco privilegiados bajo ciertas condiciones de error. • https://community.rsa.com/docs/DOC-106759 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2019-3725 – Command Injection vulnerability
https://notcve.org/view.php?id=CVE-2019-3725
15 May 2019 — RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server. Las versiones de RSA Netwitness Platform anteriores a la versión 11.2.1.1 y las de RSA Security Analytics anteriores a 10.6.6.1 son vulnerables a la Inyección de comandos debido a la falta ... • http://www.securityfocus.com/bid/108355 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2019-3724 – Authorization Bypass VulnerabilityRSA Netwitness Platform
https://notcve.org/view.php?id=CVE-2019-3724
15 May 2019 — RSA Netwitness Platform versions prior to 11.2.1.1 is vulnerable to an Authorization Bypass vulnerability. A remote low privileged attacker could potentially exploit this vulnerability to gain access to administrative information including credentials. En RSA Netwitness Platform versiones anteriores a 11.2.1.1, esta expuesta a una vulnerabilidad de omisión de autorización. Un atacante remoto con bajos privilegios podría explotar esta vulnerabilidad para conseguir acceso a la información administrativa, incl... • https://packetstorm.news/files/id/152943 •

CVE-2019-3715 – Information Exposure Vulnerability
https://notcve.org/view.php?id=CVE-2019-3715
13 Mar 2019 — RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks. RSA Archer, en CVErsiones anteriores a la 6.5 SP1, contiene una vulnerabilidad de exposición de información. La información de las sesiones de usuario se almacena en texto plano en los archivos de registro de RSA A... • http://www.securityfocus.com/bid/107443 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2019-3716 – Information Exposure Vulnerability
https://notcve.org/view.php?id=CVE-2019-3716
13 Mar 2019 — RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks. RSA Archer, en CVErsiones anteriores a la 6.5 SP2, contiene una vulnerabilidad de exposición de información. La contraseña de conexión a la base de datos podría almacenarse en texto plano en los archivos de... • http://www.securityfocus.com/bid/107406 • CWE-532: Insertion of Sensitive Information into Log File •