Important Update: Archer Community Scheduled Maintenance on November 23–24 - New Community Launching Soon! Learn More..

cancel
Showing results for 
Search instead for 
Did you mean: 
Platform Announcements
Review announcements about Archer product releases

Articles

[Historic] Archer Security Update for Node.js

Dell EMC Identifier: DSA-2018-178 CVE Identifier: CVE-2017-18214 Severity: High Severity Rating: See NVD http://web.nvd.nist.gov/view/vuln/search. Affected Products: All RSA Archer 6.x versions prior to 6.4.1 or 6.4.1.1 (including 6.1.x, 6.2.x, 6.3.x...

Anonymous by Not applicable
  • 662 Views
  • 0 comments
  • 0 kudos
Summary Archer announces End of Product Support (EOPS) for Archer Release 6.11, as well as all derivative patches, effective March 31, 2024. Extended Support will be offered for this version, please contact your Account team for details. Customers under current maintenance contracts can update to an Archer 6.14 version as the latest Platform release.   Platforms • Archer Release 6.11 • Archer Release 6.11 Patch 1 • Archer Release 6.11 Patch 2 and all Patch 2 Hot Fix releases • Archer Release 6.11 Patch 3 • Archer Release 6.11 Patch 4   Recommendations Customers who have deployed Archer Release 6.11.x are encouraged to update to Archer Release 6.14 or later.   Documentation For additional documentation and more, visit the Archer Help Center and the Archer Community.   End of Product Support Policy Archer has a defined End of Primary Support policy associated with all major versions. For additional details, refer to the Product Version Life Cycle.
View full article
  Summary Archer Platform Update Release 2024.08 delivers bug fixes for the Archer Platform. For a detailed list of fixes within this release, please see the Release Notes link below. Note: This release is only available for Archer on-premises clients. Fixes in this release will be included in the 2024.09 release when SaaS upgrades to that release later this year.   Release Notes Archer 2024.08 Release Notes   Download Archer Platform downloads are available on the myArcher Customer Portal. Please review Instructions to access Archer Platform Downloads through the myArcher Customer Portal to learn how to register and access the download. This release is available to Archer on-premises customers on August 8, 2024.   Documentation Archer 2024.08 Platform Help Archer 2024.08 Control Panel Help Archer Qualified and Supported Environments Please continue to use the following Release 2024.06 related documents for this release: • Presentation – Archer Release 2024.06 Overview • Archer 2024.06 & Later Known Issues (PDF format) • Archer 2024.06 & Later Known Issues (Excel format)   Blogs • Trigger Data Feed from Advanced Workflow • Modernizing Search in SaaS • Changes to Archer Platform Releases • Retiring the Task-Driven Landing Page (TDLP) • Altered Behavior for File:// External Links • Archer Platform and Engage Downloads moving to myArcher   Free Friday Tech Huddles Free Friday Tech Huddles provide free training that is offered by the Product Management and Support teams. Register here to attend future sessions. FFTH: Archer Platform Release June 2024 - Highlights   End of Product Support Policy Archer has a defined End of Primary Support policy associated with all major versions. For additional details, refer to the Product Version Life Cycle.
View full article
  Summary Archer Platform Update Release 2024.06.02 delivers performance fixes for the Archer Platform. Important SaaS Clients: This release is first being deployed to the US and EU SaaS environments as outlined in the SaaS Announcement. Please note the version in the About Archer popup window will remain 2024.06. The build version in the copy function will be different.   Release Notes This release contains the following fixes: S3 folder management changes Config Service client interservice optimizations Additional web.config optimizations Additional instrumentation   Download Archer Platform downloads are available on the myArcher Customer Portal. Please review Instructions to access Archer Platform Downloads through the myArcher Customer Portal to learn how to register and access the download. Note: This release is being made available for US and EU SaaS environments first. Rollouts to additional worldwide SaaS environments will be announced at a future point in time. Any appropriate fixes will be made available to OnPrem clients in a future release.   Documentation Please continue to use all the Release 2024.06 related documents for this release: • Presentation – Archer Release 2024.06 Overview • Archer 2024.06 Platform Help • Archer 2024.06 Control Panel Help • Archer Qualified and Supported Environments • Archer 2024.06 & Later Known Issues (PDF format) • Archer 2024.06 & Later Known Issues (Excel format)   Blogs • Trigger Data Feed from Advanced Workflow • Modernizing Search in SaaS • Changes to Archer Platform Releases • Retiring the Task-Driven Landing Page (TDLP) • Altered Behavior for File:// External Links • Archer Platform and Engage Downloads moving to myArcher   Free Friday Tech Huddles Free Friday Tech Huddles provide free training that is offered by the Product Management and Support teams. Register here to attend future sessions. FFTH: Archer Platform Release June 2024 - Highlights End of Product Support Policy Archer has a defined End of Primary Support policy associated with all major versions. For additional details, refer to the Product Version Life Cycle.
View full article
Archer Identifier SA-15   CVE Identifier CVE-2024-41706, CVE-2024-41707, CVE-2024-41705   Severity High   Severity Rating Individual CVE scores noted below.   Affected Products Archer Platform versions greater than 6   Summary Archer Platform contains fixes for multiple security vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.   Details Archer Platform has been updated for the following vulnerabilities: • Stored Cross-site Scripting Vulnerability CVE-2024-41706 A stored XSS was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P4 (6.14.0.4) is also a fixed release. CVSSv3.1 Base Score: 7.3 (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N) • Stored Cross-site Scripting Vulnerability CVE-2024-41705 A stored XSS was discovered in Archer Platform 6.8 before version 2024.06. There is a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14.P4 (6.14.0.4) and 6.13 P4 (6.13.0.4) are also fixed releases. This vulnerability is similar to, but not identical to, CVE-2023-30639. CVSSv3.1 Base Score: 7.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)   • HTML Content Injection Vulnerability CVE-2024-41707 An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. CVSSv3.1 Base Score: 4.8 (AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N) For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.   Recommendation For CVE-2024-41706, the following Archer releases contain a resolution to this vulnerability: • Archer version 2024.06 or higher • Archer version 6.14 P4 (6.14.0.4) or higher For CVE-2024-41705, the following Archer releases contain a resolution to this vulnerability: • Archer version 2024.06 or higher • Archer version 6.14 P4 (6.14.0.4) or higher • Archer version 6.13 P4 (6.13.0.4) or higher For CVE-2024-41707, the following Archer releases contain a resolution to this vulnerability: • Archer version 2024.06 or higher Archer recommends all customers upgrade at the earliest opportunity.   Severity Rating For an explanation of Severity Ratings, refer to the Archer Vulnerability Disclosure Policy. Archer recommends all customers consider both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.   EOPS Policy Archer has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.   Legal Information Read and use the information in this Archer Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact Archer Technical Support. Archer distributes Archer Security Advisories in order to bring to the attention of users of the affected Archer products, important security information. Archer recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. Archer disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Archer, its affiliates or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Archer, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.      
View full article
Overview Archer Release 6.13 delivers enhancements for Archer use cases and the Archer Platform. For a detailed list of features within this release, please see the Advisory Announcement information below.   Advisories Advisories announce a release and provide insight into the enhancements that are available within the release.  Archer Announces Availability of Archer Release 6.13  Archer Announces Availability of Archer Release 6.13 Patch 1 Archer Announces Availability of Archer Release 6.13 Patch 1 Hotfix 2 Archer Announces Availability of Archer Release 6.13 Patch 1 Hotfix 3 Archer Announces Availability of Archer Release 6.13 Patch 2 Announcing Archer Platform Release 6.13 Patch 2 Hotfix 2 Announcing Archer Platform Release 6.13 Patch 3 Announcing Archer Platform Release 6.13 Patch 3 Hotfix 1 Announcing Archer Platform Release 6.13 Patch 4   Use Case Updates The following provides links for the updated Use Case Packages that are available on the Archer Community and include:  Archer Third Party Governance Archer Third Party Risk Management Archer Third Party Engagements Archer Issues Management Archer Audit Engagements and Workpapers Archer Audit Quality and Planning Archer Crisis Management Archer Business Continuity & IT Disaster Recovery Planning Archer Incident Management Archer Business Impact Analysis Archer Operational Scenario Analysis Archer ESG Management Archer PCI Management Archer IT Controls Assurance Archer IT & Security Policy Program Management Archer Policy Program Management Archer Control Assurance Program Management Archer Financial Controls Monitoring Archer Enterprise Catalog Archer Task Management   Blogs Blogs share the latest news about a specific release or feature. 6.13 Archer Installer Update – Default Icon Replacement Upcoming Plans for Calculating Inactive Fields Next Gen Risk Experience: Modern and Responsive Global Navigation Introducing the Next Generation Dashboard Archer Platform and Engage Downloads moving to MyArcher Update on Archer Security Advisories   Documentation Use Case Help Documentation for the updated use cases can be found here: IT Security & Risk Management: PC Management 6.11 Audit Management: Audit Engagements and Workpapers 6.13 Business Resiliency: Business Impact Analysis 6.13 ESG Management IT Security & Risk Management: PCI Management 6.13 RCCM: Controls Assurance Program Management 6.13 Third Party Governance: Third Party Engagement 6.13 Third Party Governance: Third Party Risk Management 6.13 The latest Platform documentation can be found in the following locations:  Presentation - Archer Release 6.13 Overview  Archer 6.13 Release Notes (Excel Format)  Archer 6.13 Release Notes (PDF Format)  Archer Qualified and Supported Environments   Archer 6.13 Platform Help  Archer 6.13 Control Panel Help  Archer 6.13 & Later Release Notes - Patch 1 (Excel Format) Archer 6.13 & Later Release Notes - Patch 1 (PDF Format) Archer 6.13 & Later Release Notes - Patch Hotfix 2 (Excel Format) Archer 6.13 & Later Release Notes - Patch 1 Hotfix 2 (PDF Format) Archer 6.13 & Later Release Notes - Patch 1 Hotfix 3 (PDF Format) Archer 6.13 & Later Release Notes - Patch 1 Hotfix 3 (Excel Format) Archer 6.13 & Later Release Notes - Patch 2 (PDF Format) Archer 6.13 & Later Release Notes - Patch 2 (Excel Format) Archer 6.13 & Later Release Notes - Patch 2 Hotfix 2 (PDF Format) Archer 6.13 & Later Release Notes - Patch 2 Hotfix 2 (Excel Format) Archer 6.13 & Later Release Notes - Patch 3 (PDF Format) Archer 6.13 & Later Release Notes - Patch 3 (Excel Format) Archer 6.13 & Later Release Notes - Patch 3 Hotfix 1 (PDF Format) Archer 6.13 & Later Release Notes - Patch 3 Hotfix 1 (Excel Format)   Free Friday Tech Huddle Schedule and Replays Replay -- FFTH Archer Release 6.13 Release Overview Platform Updates - Next Gen Dashboards and Global Navigation Replay -- FFTH Archer Platform Release 6.13 Overview & Demo - Solutions & Use Case Updates Replay -- FFTH: Findings Message Updates in Release 6.13 Patch 1   End of Product Support Policy Archer has a defined End of Primary Support policy associated with all major versions. For additional details, refer to the Product Version Life Cycle.  
View full article
Top Contributors