CVE-2019-9884: Eclass IP
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
Affected products
- Eclass Eclass IP: before 2.5.10.2.1 (fixed in 2.5.10.2.1)
Published 2019-07-25. Last modified 2026-06-17.