Kirona Dynamic Resource Scheduler is susceptible to information disclosure. An unauthenticated user can directly access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd), which contains sensitive information with exposed SQL queries, such as database version, table name, and column name.
id: CVE-2019-17503
info:
name: Kirona Dynamic Resource Scheduler - Information Disclosure
autho
...