Vulnerability Description
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openmicroscopy | Omero.Server | >= 5.1.0, <= 5.6.0 |
Related Weaknesses (CWE)
References
- https://www.openmicroscopy.org/security/advisories/2019-SV2/Vendor Advisory
- https://www.openmicroscopy.org/security/advisories/2019-SV2/Vendor Advisory
FAQ
What is CVE-2019-9943?
CVE-2019-9943 is a vulnerability with a CVSS score of 7.5 (HIGH). In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operation...
How severe is CVE-2019-9943?
CVE-2019-9943 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9943?
Check the references section above for vendor advisories and patch information. Affected products include: Openmicroscopy Omero.Server.