CVE-2012-2292

RSA Archer SmartSuite Framework 4.x & GRC <5.2SP1 - Same Origin Policy Bypass via Silverlight

Title source: llm
STIX 2.1

Description

The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the Archer application, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

References (1)

Core 1
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0001.html

Scores

EPSS 0.0022
EPSS Percentile 45.1%

Details

CWE
CWE-264
Status published
Products (5)
emc/rsa_archer_egrc 5.0
emc/rsa_archer_egrc 5.1
emc/rsa_archer_egrc 5.2
emc/rsa_archer_smartsuite 4.3
emc/rsa_archer_smartsuite 4.5
Published Feb 06, 2013
Tracked Since Feb 18, 2026