{"api_version":"1","generated_at":"2026-07-23T11:00:52+00:00","cve":"CVE-2020-9519","urls":{"html":"https://cve.report/CVE-2020-9519","api":"https://cve.report/api/cve/CVE-2020-9519.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9519","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9519"},"summary":{"title":"CVE-2020-9519","description":"HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2020-03-16 13:15:00","updated_at":"2023-11-07 03:26:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://softwaresupport.softwaregrp.com/doc/KM03607789","name":"https://softwaresupport.softwaregrp.com/doc/KM03607789","refsource":"","tags":[],"title":"MySupport - Micro Focus Software Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9519","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9519","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9519","vulnerable":"1","versionEndIncluding":"9.63","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"service_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-9519","ASSIGNER":"security@microfocus.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Micro Focus International","product":{"product_data":[{"product_name":"Service Manager (Server).","version":{"version_data":[{"version_value":"9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"HTTP methods reveled in Web services."}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://softwaresupport.softwaregrp.com/doc/KM03607789","url":"https://softwaresupport.softwaregrp.com/doc/KM03607789"}]},"description":{"description_data":[{"lang":"eng","value":"HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data."}]}},"nvd":{"publishedDate":"2020-03-16 13:15:00","lastModifiedDate":"2023-11-07 03:26:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:service_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"9.40","versionEndIncluding":"9.63","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9519","Ordinal":"169910","Title":"CVE-2020-9519","CVE":"CVE-2020-9519","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9519","Ordinal":"1","NoteData":"HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9519","Ordinal":"2","NoteData":"2020-03-16","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9519","Ordinal":"3","NoteData":"2020-03-16","Type":"Other","Title":"Modified"}]}}}