Vulnerability Details CVE-2019-3756
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.4%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2019-3756
-
-
cpe:2.3:a:rsa:archer:6.1.0.0
-
cpe:2.3:a:rsa:archer:6.1.0.3
-
-
-
-
cpe:2.3:a:rsa:archer:6.4.0.1
-
cpe:2.3:a:rsa:archer:6.4.0.2
-
-
cpe:2.3:a:rsa:archer:6.6.0.2