CVE-2019-3716: Rsa Archer Grc Platform

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks.

Affected products

  • Rsa Archer Grc Platform: before 6.5.2.0 (fixed in 6.5.2.0)

Published 2019-03-13. Last modified 2026-06-17.