Metrics
Affected Vendors & Products
Fri, 25 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Fri, 25 Oct 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This is a different issue than CVE-2024-10069. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG DecryptApplicationService.java actionPassDecryptApplication1 sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-10-25T11:00:14.253Z
Updated: 2024-10-25T18:51:59.393Z
Reserved: 2024-10-25T05:53:39.275Z
Link: CVE-2024-10377
Updated: 2024-10-25T18:51:40.207Z
Status : Analyzed
Published: 2024-10-25T11:15:15.920
Modified: 2024-11-05T19:41:20.677
Link: CVE-2024-10377
No data.