CVE-2019-17503
Last modified
CVE-2019-17503 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. EPSS estimates a 49.24% chance of exploitation in the next 30 days.
Description
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kirona | Dynamic Resource Scheduling | 5.5.3.5 |
References
- http://packetstormsecurity.com/files/154838/Kirona-DRS-5.5.3.5-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/Ramikan/Vulnerabilities/blob/master/Kirona-DRS%205.5.3.5%20Multiple%20VulnerabilitiesExploit, Third Party Advisory
- http://packetstormsecurity.com/files/154838/Kirona-DRS-5.5.3.5-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/Ramikan/Vulnerabilities/blob/master/Kirona-DRS%205.5.3.5%20Multiple%20VulnerabilitiesExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17503?
How severe is CVE-2019-17503?
How do I fix CVE-2019-17503?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-17497Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO …6.5
- CVE-2019-17498In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNE…8.1
- CVE-2019-17499The setter.xml component of the Common Gateway Interface on …8.8
- CVE-2019-1750A vulnerability in the Easy Virtual Switching System (VSS) o…7.4
- CVE-2019-17501Centreon 19.04 allows attackers to execute arbitrary OS comm…8.8
- CVE-2019-17502Hydra through 0.1.8 has a NULL pointer dereference and daemo…7.5
- CVE-2019-17504An issue was discovered in Kirona Dynamic Resource Schedulin…6.1
- CVE-2019-17505D-Link DAP-1320 A2-V1.21 routers have some web interfaces wi…7.5
- CVE-2019-17506There are some web interfaces without authentication require…9.8
- CVE-2019-17507An issue was discovered on D-Link DIR-816 A1 1.06 devices. A…7.5
- CVE-2019-17508On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/se…9.8
- CVE-2019-17509D-Link DIR-846 devices with firmware 100A35 allow remote att…9.8
Are you affected by CVE-2019-17503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
