Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2023-45357

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.
Attacker Value
Unknown

CVE-2023-37224

Disclosure Date: July 14, 2023 (last updated October 08, 2023)
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
Attacker Value
Unknown

CVE-2023-37223

Disclosure Date: July 14, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
Attacker Value
Unknown

CVE-2023-32761

Disclosure Date: July 14, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
Attacker Value
Unknown

CVE-2023-32760

Disclosure Date: July 14, 2023 (last updated October 08, 2023)
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
Attacker Value
Unknown

CVE-2023-32759

Disclosure Date: July 14, 2023 (last updated October 08, 2023)
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
Attacker Value
Unknown

CVE-2023-30639

Disclosure Date: May 01, 2023 (last updated October 08, 2023)
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release.