peter bassill · operator
$ cve CVE-2019-17503 JSON

CVE-2019-17503 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 48.3% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS48.3% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-425
On CISA KEVno
Public exploityes
Published2019-10-11
Last modified2026-06-17

Affected (1)

VendorProduct
kironadynamic resource scheduling

Public exploits

SourceTitleDate
exploit-dbKirona-DRS 5.5.3.5 - Information Disclosure2019-10-14

References

→ the Explorer  ·  watch your stack  ·  NVD