CVE-2019-11658

Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:content_manager:9.1:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:content_manager:9.2:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:content_manager:9.3:*:*:*:*:*:*:*

History

21 Nov 2024, 04:21

Type Values Removed Values Added
References () https://softwaresupport.softwaregrp.com/doc/KM03496282 - () https://softwaresupport.softwaregrp.com/doc/KM03496282 -

07 Nov 2023, 03:03

Type Values Removed Values Added
References (CONFIRM) https://softwaresupport.softwaregrp.com/doc/KM03496282 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03496282 -

Information

Published : 2019-08-30 09:15

Updated : 2024-11-21 04:21


NVD link : CVE-2019-11658

Mitre link : CVE-2019-11658

CVE.ORG link : CVE-2019-11658


JSON object : View

Products Affected

microfocus

  • content_manager
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor