CVE-2019-5916
Last modified
CVE-2019-5916 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors.. EPSS estimates a 1.48% chance of exploitation in the next 30 days.
Description
Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| D-Circle | Power Egg | 2.0.1 | — |
| D-Circle | Power Egg | 2.0.2 | Patch3 |
| D-Circle | Power Egg | 2.1 | Patch4 |
| D-Circle | Power Egg | 2.2 | Patch7 |
| D-Circle | Power Egg | 2.3 | Patch9 |
| D-Circle | Power Egg | 2.4 | Patch13 |
| D-Circle | Power Egg | 2.5 | Patch12 |
| D-Circle | Power Egg | 2.6 | Patch8 |
| D-Circle | Power Egg | 2.7 | Patch6 |
| D-Circle | Power Egg | 2.8 | Patch6 |
| D-Circle | Power Egg | 2.8c | Patch5 |
| D-Circle | Power Egg | 2.9 | Patch4 |
References
- http://jvn.jp/en/jp/JVN63860183/index.htmlThird Party Advisory
- http://jvn.jp/en/jp/JVN63860183/index.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5916?
How severe is CVE-2019-5916?
How do I fix CVE-2019-5916?
Are you affected by CVE-2019-5916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
