CVE-2016-0899: Emc Rsa Archer Egrc

Medium severity, CVSS 6.3. EPSS: 0.8% chance of exploitation in the next 30 days.

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.

Affected products

  • Emc Rsa Archer Egrc: version 5.5 only; version 5.5.1 only; version 5.5.1.3 only; version 5.5.2.3 only

Published 2016-07-04. Last modified 2026-06-17.