CVE-2019-13163

MEDIUMCVSS 5.9/10EPSS 0.60%

Last modified

CVE-2019-13163 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.

Description

The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.60%

44.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FujitsuGp7000f FirmwareAll versions
FujitsuPrimepower FirmwareAll versions
FujitsuGps FirmwareAll versions
FujitsuSparc Enterprise M3000 FirmwareAll versions
FujitsuSparc Enterprise M4000 FirmwareAll versions
FujitsuSparc Enterprise M5000 FirmwareAll versions
FujitsuSparc Enterprise M8000 FirmwareAll versions
FujitsuSparc Enterprise M9000 FirmwareAll versions
FujitsuSparc M12-1 FirmwareAll versions
FujitsuSparc M12-2 FirmwareAll versions
FujitsuSparc M12-2s FirmwareAll versions
FujitsuPrimergy Rx2530 M5 FirmwareAll versions
FujitsuPrimergy Rx2540 M5 FirmwareAll versions
FujitsuPrimergy Rx4770 M5 FirmwareAll versions
FujitsuPrimergy Tx2550 M5 FirmwareAll versions
FujitsuGranpower 5000 FirmwareAll versions
FujitsuCelsius FirmwareAll versions
FujitsuPrimequest FirmwareAll versions
FujitsuInterstage Application Development Cycle Manager10.0
FujitsuInterstage Application Development Cycle Manager10.0a
FujitsuInterstage Application Development Cycle Manager10.1
FujitsuInterstage Application Development Cycle Manager10.1.1
FujitsuInterstage Application Development Cycle Manager10.2
FujitsuInterstage Application Development Cycle Manager10.3
FujitsuInterstage Application Development Cycle Manager10.3.1
FujitsuInterstage Application Development Cycle Manager10.3.1a
FujitsuInterstage Application Server8.0.0
FujitsuInterstage Application Server8.0.1
FujitsuInterstage Application Server8.0.3
FujitsuInterstage Application Server9.0.0
FujitsuInterstage Application Server9.0.0b
FujitsuInterstage Application Server9.1.0
FujitsuInterstage Application Server9.1.0b
FujitsuInterstage Application Server9.2.0
FujitsuInterstage Application Server9.2.0a
FujitsuInterstage Application Server9.3.0
FujitsuInterstage Application Server10.0.0
FujitsuInterstage Application Server10.1.0
FujitsuInterstage Application Server11.0.0
FujitsuInterstage Application Server11.1.0
FujitsuInterstage Application Server12.0.0
FujitsuInterstage Application Server12.1.0
FujitsuInterstage Application Server12.2.0
FujitsuInterstage Business Application Manager1.0l10
FujitsuInterstage Business Application Manager1.0l20
FujitsuInterstage Business Application Manager1.0l21
FujitsuInterstage Business Application Manager1.1
FujitsuInterstage Business Application Manager2.0.0
FujitsuInterstage Business Application Manager2.0.1
FujitsuInterstage List Works9.0.1

Showing 50 of 178 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-13163?
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.
How severe is CVE-2019-13163?
CVE-2019-13163 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.60% probability of exploitation in the next 30 days.
How do I fix CVE-2019-13163?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-13163?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST