S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2019-9632 Scanner

CVE-2019-9632 Scanner - Arbitrary File Download vulnerability in ESAFENET Electronic Document Security Management System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9632
7.5
CVSS

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ESAFENET Electronic Document Security Management System is software commonly used by organizations to manage and secure electronic documents. It helps users to store, retrieve, and manage documents with security controls. The software is typically utilized in environments where document confidentiality and integrity are crucial. It ensures that documents are accessible only to authorized personnel and enhances collaboration within organizations. The software is designed to integrate seamlessly with existing IT infrastructure, providing a robust solution for document security. ESAFENET aims to streamline document workflows while maintaining stringent security standards required in sensitive data management.

The Arbitrary File Download vulnerability in the ESAFENET Electronic Document Security Management System allows unauthorized users to download files from the server. This can include confidential or sensitive files that were not intended for public access. The vulnerability arises due to improper handling of file requests, specifically through the mishandling of the InstallationPack parameter in a download.jsp request. This oversight can lead to significant data breaches as attackers might exploit this flaw to retrieve sensitive information. The likelihood of exploitation is heightened if the system is accessible from the internet, especially in setups lacking additional security layers.

Technical details reveal that the vulnerability can be exploited via a POST request to the /CDGServer3/ClientAjax endpoint. The request leverages the InstallationPack parameter to specify the file path for download, bypassing security checks. The vulnerable parameter, controlled by the attacker, enables retrieval of specifically crafted files by directing them to path traversals like ../ to access restricted directories. A successful attack depends on the presence of improperly sanitized input which allows the attacker to navigate the directory structure. The system's default configuration, without adequate input validation, enhances the risk across affected versions V3 and V5.

If exploited, this vulnerability allows an attacker to download arbitrary files from the server, potentially exposing sensitive information. Such exposure could lead to further exploitation, including data theft, unauthorized data manipulation, or reconnaissance for subsequent attacks. It undermines the organization's confidentiality agreements and data protection obligations. Additionally, reliance on sensitive data integrity could be compromised, leading to substantial financial and reputational damage. Organizations may also face regulatory non-compliance consequences if sensitive user data is leaked as part of these attacks.

REFERENCES

Solution Advice
  • Implement input validation and sanitization to restrict file paths that can be supplied by users.
  • Apply patch updates or security releases from ESAFENET to address known vulnerabilities.
  • Utilize web application firewalls (WAFs) that detect and filter harmful requests targeting file download endpoints.
  • Configure access controls and permissions to limit file access to authenticated users only.
  • Conduct regular security assessments and audits to identify and address potential exposure to the arbitrary file download.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-9632 Scanner - Arbitrary File Download vulnerability in ESAFENET Electronic Document Security Management System | S4E