PT-2024-16393 · Safenet · Esafenet Cdg

0Menc

+1

·

Published

2024-10-31

·

Updated

2024-11-05

·

CVE-2024-10596

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESAFENET CDG 5
Description A critical issue was found in ESAFENET CDG, affecting the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to SQL injection. The attack may be launched remotely.
Recommendations For ESAFENET CDG 5, update to the latest patched version immediately to mitigate risks. As a temporary workaround, consider disabling the delEntryptPolicySort function until a patch is available. Restrict access to the /com/esafenet/servlet/system/EncryptPolicyTypeService.java file to minimize the risk of exploitation. Avoid using the argument id in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10596

Affected Products

Esafenet Cdg