CVE-2019-9943

HIGH

OMERO.server <5.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0083
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-276
Status published
Products (1)
openmicroscopy/omero.server 5.1.0 - 5.6.0
Published Jun 17, 2020
Tracked Since Feb 18, 2026