CVE-2018-11060: Rsa Archer

High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.

RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their privileges.

Affected products

  • Rsa Archer: from 6.1.0.0, before 6.1.0.3 (fixed in 6.1.0.3); from 6.2.0.0, before 6.2.0.10 (fixed in 6.2.0.10); from 6.3.0.0, before 6.3.0.7 (fixed in 6.3.0.7); version 6.4.0.0 only

Published 2018-07-24. Last modified 2026-06-17.