peter bassill · operator
$ cve CVE-2019-16383 JSON

CVE-2019-16383 EXPLOIT

9.4
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.

Scoring

CVSS9.4 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
EPSS5.19% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2019-09-24
Last modified2026-06-17

Affected (1)

VendorProduct
ipswitchmoveit transfer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD