CVE-2019-9632

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/03/2019
Last modified:
24/08/2020

Description

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:esafenet:electronic_document_security_management_system:v3:*:*:*:*:*:*:*
cpe:2.3:a:esafenet:electronic_document_security_management_system:v5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools