CVE-2019-11658

MEDIUM

Micro Focus Content Manager <9.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state.

References (1)

Core 1
Core References
Various Sources x_refsource_confirm
https://softwaresupport.softwaregrp.com/doc/KM03496282

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
microfocus/content_manager 9.1
microfocus/content_manager 9.2
microfocus/content_manager 9.3
Published Aug 30, 2019
Tracked Since Feb 18, 2026