First published: Fri Nov 01 2024(Updated: )
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10659 is classified as a critical vulnerability due to its potential to allow SQL injection.
To fix CVE-2024-10659, it is recommended to update the ESAFENET CDG software to the latest patched version.
CVE-2024-10659 affects the delSystemEncryptPolicy function in the CDGAuthoriseTempletService.java file.
CVE-2024-10659 can lead to unauthorized access to the database through SQL injection, compromising sensitive data.
Until a patch is applied for CVE-2024-10659, it is advisable to implement input validation on the affected parameter.