CVE-2019-5919

Description

An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value via unspecified vectors.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.161

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-5919 are fixed in Nablarch-nablarch-fw-web 1.5.1Windows
Vulnerabilities CVE-2019-5919 are fixed in Nablarch-nablarch-fw-web for Linux 1.5.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234