Archer
Vendor:
First CVE: Jul 24, 2018 · Active for 7 years
33
Total CVEs
More Total CVEs than 96% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Archer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 24, 2018
7 years ago
Most Recent CVE
Aug 25, 2022
1,429 days ago
CVE Severity & Scoring
Archer33 CVEs
79%
18%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (6.1%)
Network31 (93.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (97.0%)
High1 (3.0%)
Unknown0 (0.0%)
User Interaction
None18 (54.5%)
Unknown0 (0.0%)
Required15 (45.5%)
Privileges Required
Low21 (63.6%)
High2 (6.1%)
None10 (30.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3758CRITICAL RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient crede | Sep 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-30584HIGH Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to | May 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-11060HIGH RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vu | Jul 24, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-5335HIGH RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability b | May 4, 2020 | 8.8 | 27 | NO | NO |
CVE-2021-33615HIGH RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. | Jun 2, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-5332HIGH RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit t | May 4, 2020 | 7.2 | 24 | NO | NO |
CVE-2021-38362MEDIUM In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR | Mar 30, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-26949MEDIUM Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulne | Mar 30, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-37316MEDIUM Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata | Aug 25, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-30585MEDIUM The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vuln | May 26, 2022 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Archer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.9 | 1 | 6.1 | 0.8% | 0 | 0 |
| 6.4.0.0 | 2 | 7.1 | 2.2% | 0 | 0 |