CVE Vulnerabilities

CVE-2019-9632

Published: Mar 08, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Affected Software

NameVendorStart VersionEnd Version
Electronic_document_security_management_systemEsafenetv3 (including)v3 (including)
Electronic_document_security_management_systemEsafenetv5 (including)v5 (including)

References