Summary
Detail | |||
---|---|---|---|
Vendor | Emc | First view | 2014-12-12 |
Product | Rsa Archer Egrc | Last view | 2016-07-04 |
Version | 5.5.1 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:emc:rsa_archer_egrc |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.3 | 2016-07-04 | CVE-2016-0899 | EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files. |
4.3 | 2014-12-12 | CVE-2014-4633 | Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-200 | Information Exposure |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |