CVE-2019-9944: Openmicroscopy Omero.server
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.
Affected products
- Openmicroscopy Omero.server: from 5.0.0, up to and including 5.6.0
Published 2020-06-17. Last modified 2026-06-17.