Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3816

31
FAUCET Score

CVE-2019-3816 is an arbitrary file disclosure vulnerability affecting Openwsman versions up to 2.6.9, as well as products from Fedora, openSUSE, and Red Hat. A remote, unauthenticated attacker can exploit this flaw by sending a specially crafted HTTP request, leveraging the daemon's root working directory to access sensitive files. With a CVSS score of 7.5 (High), this vulnerability presents a significant risk of data confidentiality compromise. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not listed in CISA's KEV catalog, there's limited community discussion and media coverage, suggesting it's not widely exploited in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.6.9CPE matchmatch criteria
cpe:2.3:a:openwsman_project:openwsman:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
8.1CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
8.2CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
14.74%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.1474 is in the 95th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: azl3 openwsman 2.6.8-13 on Azure Linux 3.0Fixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: 17063-16823Fixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: 17064-16817Fixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: 17064-17084Fixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.6.8-13
microsoftpatch availablevia msrc
Product: cbl2 openwsman 2.6.8-13 on CBL Mariner 2.0Fixed in: 2.6.8-13
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openwsman-0:2.6.5-5.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openwsman-0:2.6.3-6.git4391e5c.el7_6
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openwsman
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty) DirectorFixed in: openwsman
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka) DirectorFixed in: openwsman

Vendor Advisories (5)

microsoft2024-Dec/CVE-2019-3816

CVE-2019-3816

Dec 10, 2024
microsoft2024-Nov/CVE-2019-3816

CVE-2019-3816

Nov 12, 2024
microsoft2024-Oct/CVE-2019-3816

CVE-2019-3816

Oct 8, 2024
microsoft2019-Mar/CVE-2019-3816Important

Openwsman versions up to and including 2.6.9 are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.

Mar 12, 2019
redhatCVE-2019-3816Important

openwsman: Disclosure of arbitrary files outside of the registered URIs

Mar 12, 2019

References

bugzilla.suse.com / show_bug.cgi
Issue TrackingThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00065.html
Mailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2019:0638
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0972
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2V5HJ355RSKMFQ7GRJAHRZNDVXASF7TA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/B2HEZ7D7GF3HDF36JLGYXIK5URR66DS4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CXQP7UDPRZIZ4LM7FEJCTC2EDUYVOR2J
securityfocus.com / bid/107368
Third Party AdvisoryVDB Entry
securityfocus.com / bid/107409
Third Party AdvisoryVDB Entry