CVE-2019-9632: Esafenet Electronic Document Security Management System

High severity, CVSS 7.5. EPSS: 39.9% chance of exploitation in the next 30 days.

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Affected products

  • Esafenet Electronic Document Security Management System: version v3 only; version v5 only

Published 2019-03-08. Last modified 2026-06-17.