High severity8.8NVD Advisory· Published Jan 5, 2020· Updated Jun 17, 2026
CVE-2019-20155
CVE-2019-20155
Description
An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:determine:contract_lifecycle_management:5.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:determine:contract_lifecycle_management:5.4:*:*:*:*:*:*:*
- (no CPE)range: = 5.4
- Determine/Contract Lifecycle Management (CLM)description
Patches
Vulnerability mechanics
References
1- www.n00py.io/2020/01/zero-day-exploit-in-determine-selectica-contract-lifecycle-management-sclm-v5-4/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.