PT-2024-16394 · Safenet · Esafenet Cdg 5

0Menc

·

Published

2024-10-31

·

Updated

2024-11-06

·

CVE-2024-10597

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESAFENET CDG 5
Description A critical vulnerability has been found in ESAFENET CDG 5, affecting the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to SQL injection. It is possible to initiate the attack remotely.
Recommendations To mitigate the risk, update to the latest version and apply all recommended patches. As a temporary workaround, consider restricting access to the vulnerable function delPolicyAction until a patch is available. Ensure you update to the latest version to safeguard your environment.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10597

Affected Products

Esafenet Cdg 5