9.1

CVE-2019-5919

An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nablarch ProjectNablarch Version5
Nablarch ProjectNablarch Version5u1
Nablarch ProjectNablarch Version5u13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.567
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

http://jvn.jp/en/jp/JVN56542712/index.html
Third Party Advisory
https://nablarch.atlassian.net/browse/NAB-313
Third Party Advisory