In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-29T23:33:34
Updated: 2024-08-04T03:15:28.962Z
Reserved: 2021-09-24T00:00:00
Link: CVE-2021-41594
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-30T00:15:08.960
Modified: 2024-11-21T06:26:29.817
Link: CVE-2021-41594
Redhat
No data.