{"api_version":"1","generated_at":"2026-07-23T11:35:46+00:00","cve":"CVE-2019-11663","urls":{"html":"https://cve.report/CVE-2019-11663","api":"https://cve.report/api/cve/CVE-2019-11663.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11663","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11663"},"summary":{"title":"CVE-2019-11663","description":"Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2019-09-18 22:15:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-311","CWE-522"],"metrics":[],"references":[{"url":"https://softwaresupport.softwaregrp.com/doc/KM03518316","name":"https://softwaresupport.softwaregrp.com/doc/KM03518316","refsource":"","tags":[],"title":"MySupport - Micro Focus Software Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11663","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11663","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11663","vulnerable":"1","versionEndIncluding":"9.62","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"service_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-11663","ASSIGNER":"security@microfocus.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Micro Focus","product":{"product_data":[{"product_name":"Service Manager","version":{"version_data":[{"version_value":"9.30"},{"version_value":"9.31"},{"version_value":"9.32"},{"version_value":"9.33"},{"version_value":"9.34"},{"version_value":"9.35"},{"version_value":"9.40"},{"version_value":"9.41"},{"version_value":"9.50"},{"version_value":"9.51"},{"version_value":"9.52"},{"version_value":"9.60"},{"version_value":"9.61"},{"version_value":"9.62"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Clear text credentials"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://softwaresupport.softwaregrp.com/doc/KM03518316","url":"https://softwaresupport.softwaregrp.com/doc/KM03518316"}]},"description":{"description_data":[{"lang":"eng","value":"Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure."}]}},"nvd":{"publishedDate":"2019-09-18 22:15:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-311","CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:service_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"9.30","versionEndIncluding":"9.62","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11663","Ordinal":"149978","Title":"CVE-2019-11663","CVE":"CVE-2019-11663","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11663","Ordinal":"1","NoteData":"Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11663","Ordinal":"2","NoteData":"2019-09-18","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11663","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}