CVE-2019-9632 describes an arbitrary file download vulnerability in ESAFENET CDG V3 and V5, specifically within the electronic_document_security_management_system. This flaw allows an unauthenticated attacker to download arbitrary files by manipulating the fileName parameter in download.jsp, due to improper handling of the InstallationPack parameter in a /CDGServer3/ClientAjax request. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low complexity, potentially leading to a complete compromise of confidentiality. While not listed on CISA's KEV catalog, a Nuclei template exists for high-severity exploitation, and its EPSS score of 0.79234 indicates a high probability of exploitation. There is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v3CPE matchmatch criteria | cpe:2.3:a:esafenet:electronic_document_security_management_system:v3:*:*:*:*:*:*:* | ||
v5CPE matchmatch criteria | cpe:2.3:a:esafenet:electronic_document_security_management_system:v5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.