CVE-2019-13163

The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.

Published: 2020-02-07 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-13163 is rated Low Risk (38.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-13163

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2023-03-07 0.89% 0.13% -0.76%
2 2022-04-01 10.85% 0.89% -9.97%
3 2022-02-04 10.85%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-13163

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.9 3.1 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
2.2 3.6 [email protected]
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2019-13163

Affected software / configurations for CVE-2019-13163

Vendor Product Version Raw CPE
fujitsu gp7000f_firmware cpe:2.3:o:fujitsu:gp7000f_firmware:-:*:*:*:*:*:*:*
fujitsu primepower_firmware cpe:2.3:o:fujitsu:primepower_firmware:-:*:*:*:*:*:*:*
fujitsu gps_firmware cpe:2.3:o:fujitsu:gps_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_enterprise_m3000_firmware cpe:2.3:o:fujitsu:sparc_enterprise_m3000_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_enterprise_m4000_firmware cpe:2.3:o:fujitsu:sparc_enterprise_m4000_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_enterprise_m5000_firmware cpe:2.3:o:fujitsu:sparc_enterprise_m5000_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_enterprise_m8000_firmware cpe:2.3:o:fujitsu:sparc_enterprise_m8000_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_enterprise_m9000_firmware cpe:2.3:o:fujitsu:sparc_enterprise_m9000_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_m12-1_firmware cpe:2.3:o:fujitsu:sparc_m12-1_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_m12-2_firmware cpe:2.3:o:fujitsu:sparc_m12-2_firmware:-:*:*:*:*:*:*:*
fujitsu sparc_m12-2s_firmware cpe:2.3:o:fujitsu:sparc_m12-2s_firmware:-:*:*:*:*:*:*:*
fujitsu primergy_rx2530_m5_firmware cpe:2.3:o:fujitsu:primergy_rx2530_m5_firmware:-:*:*:*:*:*:*:*
fujitsu primergy_rx2540_m5_firmware cpe:2.3:o:fujitsu:primergy_rx2540_m5_firmware:-:*:*:*:*:*:*:*
fujitsu primergy_rx4770_m5_firmware cpe:2.3:o:fujitsu:primergy_rx4770_m5_firmware:-:*:*:*:*:*:*:*
fujitsu primergy_tx2550_m5_firmware cpe:2.3:o:fujitsu:primergy_tx2550_m5_firmware:-:*:*:*:*:*:*:*
fujitsu granpower_5000_firmware cpe:2.3:o:fujitsu:granpower_5000_firmware:-:*:*:*:*:*:*:*
fujitsu celsius_firmware cpe:2.3:o:fujitsu:celsius_firmware:-:*:*:*:*:*:*:*
fujitsu primequest_firmware cpe:2.3:o:fujitsu:primequest_firmware:-:*:*:*:*:*:*:*
fujitsu interstage_application_development_cycle_manager 10.0 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.0:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.0a cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.0a:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.1:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.1:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.1.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.1.1:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.1.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.1.1:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.2 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.2:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.2 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.2:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3.1:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3.1 cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3.1:*:*:*:standard:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3.1a cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3.1a:*:*:*:enterprise:*:*:*
fujitsu interstage_application_development_cycle_manager 10.3.1a cpe:2.3:a:fujitsu:interstage_application_development_cycle_manager:10.3.1a:*:*:*:standard:*:*:*
fujitsu interstage_application_server 8.0.0 cpe:2.3:a:fujitsu:interstage_application_server:8.0.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 8.0.0 cpe:2.3:a:fujitsu:interstage_application_server:8.0.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 8.0.1 cpe:2.3:a:fujitsu:interstage_application_server:8.0.1:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 8.0.1 cpe:2.3:a:fujitsu:interstage_application_server:8.0.1:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 8.0.3 cpe:2.3:a:fujitsu:interstage_application_server:8.0.3:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 8.0.3 cpe:2.3:a:fujitsu:interstage_application_server:8.0.3:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.0.0 cpe:2.3:a:fujitsu:interstage_application_server:9.0.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 9.0.0 cpe:2.3:a:fujitsu:interstage_application_server:9.0.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.0.0b cpe:2.3:a:fujitsu:interstage_application_server:9.0.0b:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.1.0 cpe:2.3:a:fujitsu:interstage_application_server:9.1.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 9.1.0 cpe:2.3:a:fujitsu:interstage_application_server:9.1.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.1.0b cpe:2.3:a:fujitsu:interstage_application_server:9.1.0b:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 9.1.0b cpe:2.3:a:fujitsu:interstage_application_server:9.1.0b:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.2.0 cpe:2.3:a:fujitsu:interstage_application_server:9.2.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 9.2.0 cpe:2.3:a:fujitsu:interstage_application_server:9.2.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.2.0a cpe:2.3:a:fujitsu:interstage_application_server:9.2.0a:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 9.2.0a cpe:2.3:a:fujitsu:interstage_application_server:9.2.0a:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 9.3.0 cpe:2.3:a:fujitsu:interstage_application_server:9.3.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 10.0.0 cpe:2.3:a:fujitsu:interstage_application_server:10.0.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 10.0.0 cpe:2.3:a:fujitsu:interstage_application_server:10.0.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 10.1.0 cpe:2.3:a:fujitsu:interstage_application_server:10.1.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 10.1.0 cpe:2.3:a:fujitsu:interstage_application_server:10.1.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 11.0.0 cpe:2.3:a:fujitsu:interstage_application_server:11.0.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 11.0.0 cpe:2.3:a:fujitsu:interstage_application_server:11.0.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 11.1.0 cpe:2.3:a:fujitsu:interstage_application_server:11.1.0:*:*:*:enterprise:*:*:*
fujitsu interstage_application_server 11.1.0 cpe:2.3:a:fujitsu:interstage_application_server:11.1.0:*:*:*:standard-j:*:*:*
fujitsu interstage_application_server 12.0.0 cpe:2.3:a:fujitsu:interstage_application_server:12.0.0:*:*:*:enterprise:*:x86:*
fujitsu interstage_application_server 12.0.0 cpe:2.3:a:fujitsu:interstage_application_server:12.0.0:*:*:*:standard-j:*:x86:*
fujitsu interstage_application_server 12.1.0 cpe:2.3:a:fujitsu:interstage_application_server:12.1.0:*:*:*:enterprise:*:x86:*
fujitsu interstage_application_server 12.1.0 cpe:2.3:a:fujitsu:interstage_application_server:12.1.0:*:*:*:standard-j:*:x86:*
fujitsu interstage_application_server 12.2.0 cpe:2.3:a:fujitsu:interstage_application_server:12.2.0:*:*:*:enterprise:*:x86:*
fujitsu interstage_application_server 12.2.0 cpe:2.3:a:fujitsu:interstage_application_server:12.2.0:*:*:*:standard-j:*:x86:*
fujitsu interstage_business_application_manager 1.0l10 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l10:*:*:*:developer:.net:*:*
fujitsu interstage_business_application_manager 1.0l10 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l10:*:*:*:enterprise:.net:*:*
fujitsu interstage_business_application_manager 1.0l10 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l10:*:*:*:standard:.net:*:*
fujitsu interstage_business_application_manager 1.0l20 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l20:*:*:*:developer:.net:*:*
fujitsu interstage_business_application_manager 1.0l20 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l20:*:*:*:enterprise:.net:*:*
fujitsu interstage_business_application_manager 1.0l20 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l20:*:*:*:standard:.net:*:*
fujitsu interstage_business_application_manager 1.0l21 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l21:*:*:*:enterprise:.net:*:*
fujitsu interstage_business_application_manager 1.0l21 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.0l21:*:*:*:standard:.net:*:*
fujitsu interstage_business_application_manager 1.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.1:*:*:*:developer:.net:*:*
fujitsu interstage_business_application_manager 1.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.1:*:*:*:enterprise:.net:*:*
fujitsu interstage_business_application_manager 1.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:1.1:*:*:*:standard:.net:*:*
fujitsu interstage_business_application_manager 2.0.0 cpe:2.3:a:fujitsu:interstage_business_application_manager:2.0.0:*:*:*:developer:.net:*:*
fujitsu interstage_business_application_manager 2.0.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:2.0.1:*:*:*:developer:.net:*:*
fujitsu interstage_business_application_manager 2.0.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:2.0.1:*:*:*:enterprise:.net:*:*
fujitsu interstage_business_application_manager 2.0.1 cpe:2.3:a:fujitsu:interstage_business_application_manager:2.0.1:*:*:*:standard:.net:*:*
fujitsu interstage_list_works 9.0.1 cpe:2.3:a:fujitsu:interstage_list_works:9.0.1:*:*:*:enterprise:*:*:*

References for CVE-2019-13163

cvelogic Threat Intelligence