In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the reported exploitation steps and found that, although the user can modify the immutable field, upon switching to View mode the field is reverted to its original value, without anything being saved to the database (and consequently there is no impact).
History

Fri, 08 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls. In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the reported exploitation steps and found that, although the user can modify the immutable field, upon switching to View mode the field is reverted to its original value, without anything being saved to the database (and consequently there is no impact).

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00025}

epss

{'score': 0.00029}


Mon, 23 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Archerirm
Archerirm archer
CPEs cpe:2.3:a:archerirm:archer:*:*:*:*:*:*:*:*
Vendors & Products Archerirm
Archerirm archer

Tue, 11 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 09:00:00 +0000

Type Values Removed Values Added
Description In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 1.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-03-11T00:00:00.000Z

Updated: 2025-08-08T12:37:21.236Z

Reserved: 2025-03-10T00:00:00.000Z

Link: CVE-2025-27893

cve-icon Vulnrichment

Updated: 2025-03-11T13:37:18.545Z

cve-icon NVD

Status : Modified

Published: 2025-03-11T09:15:25.457

Modified: 2025-08-08T13:15:29.537

Link: CVE-2025-27893

cve-icon Redhat

No data.