PT-2024-16394 · Safenet · Esafenet Cdg 5
0Menc
·
Published
2024-10-31
·
Updated
2024-11-06
·
CVE-2024-10597
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ESAFENET CDG 5
Description
A critical vulnerability has been found in ESAFENET CDG 5, affecting the function
delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to SQL injection. It is possible to initiate the attack remotely.Recommendations
To mitigate the risk, update to the latest version and apply all recommended patches. As a temporary workaround, consider restricting access to the vulnerable function
delPolicyAction until a patch is available. Ensure you update to the latest version to safeguard your environment.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esafenet Cdg 5