CVE-2019-14278: Medium severity knowage vulnerability
Published Sep 5, 2019
·Updated
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
Affected Software
1 affected component
Knowage-suite Knowage<=6.1.1
Event History
Sep 5, 2019
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Knowage vulnerability?
The vulnerability ID is CVE-2019-14278.
2
What is the severity rating for CVE-2019-14278?
The severity rating for CVE-2019-14278 is medium with a score of 5.3.
3
How can an unauthenticated user exploit this vulnerability?
An unauthenticated user can exploit this vulnerability by enumerating valid usernames via the ChangePwdServlet page.
4
What version of Knowage is affected by CVE-2019-14278?
Knowage version up to and including 6.1.1 is affected by CVE-2019-14278.
5
Where can I find more information about CVE-2019-14278?
You can find more information about CVE-2019-14278 at the following link: https://blog.contentsecurity.com.au/knowage-user-enumeration