Metrics
Affected Vendors & Products
Thu, 17 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Thu, 17 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG PolicyPushControlAction.java actionPolicyPush sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-10-17T15:00:14.030Z
Updated: 2024-10-17T15:29:43.814Z
Reserved: 2024-10-17T07:32:30.865Z
Link: CVE-2024-10070
Updated: 2024-10-17T15:29:37.978Z
Status : Analyzed
Published: 2024-10-17T15:15:13.110
Modified: 2024-10-22T14:19:40.597
Link: CVE-2024-10070
No data.