{"api_version":"1","generated_at":"2026-07-23T09:46:47+00:00","cve":"CVE-2019-11666","urls":{"html":"https://cve.report/CVE-2019-11666","api":"https://cve.report/api/cve/CVE-2019-11666.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11666","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11666"},"summary":{"title":"CVE-2019-11666","description":"Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2019-09-17 19:15:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://softwaresupport.softwaregrp.com/doc/KM03518316","name":"https://softwaresupport.softwaregrp.com/doc/KM03518316","refsource":"","tags":[],"title":"MySupport - Micro Focus Software Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11666","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11666","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11666","vulnerable":"1","versionEndIncluding":"9.62","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"service_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-11666","ASSIGNER":"security@microfocus.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Micro Focus","product":{"product_data":[{"product_name":"Service Manager","version":{"version_data":[{"version_value":"9.30"},{"version_value":"9.31"},{"version_value":"9.32"},{"version_value":"9.33"},{"version_value":"9.34"},{"version_value":"9.35"},{"version_value":"9.40"},{"version_value":"9.41"},{"version_value":"9.50"},{"version_value":"9.51"},{"version_value":"9.52"},{"version_value":"9.60"},{"version_value":"9.61"},{"version_value":"9.62"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Insecure deserialization of untrusted data."}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://softwaresupport.softwaregrp.com/doc/KM03518316","url":"https://softwaresupport.softwaregrp.com/doc/KM03518316"}]},"description":{"description_data":[{"lang":"eng","value":"Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data."}]}},"nvd":{"publishedDate":"2019-09-17 19:15:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:service_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"9.30","versionEndIncluding":"9.62","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11666","Ordinal":"149981","Title":"CVE-2019-11666","CVE":"CVE-2019-11666","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11666","Ordinal":"1","NoteData":"Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11666","Ordinal":"2","NoteData":"2019-09-17","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11666","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}