search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Telos Automated Message Handling System contains multiple vulnerabilities

Vulnerability Note VU#873161

Original Release Date: 2019-12-19 | Last Revised: 2019-12-19


Telos Automated Message Handling System (AMHS) contains multiple XSS vulnerabilities and a database information disclosure vulnerability.


Telos AMHS is a web-based messaging system that supports DoD and Intelligence Community (IC) security marking requirements. AMHS versions prior to version contain multiple XSS vulnerabilities and also fail to properly restrict access to information about other users on the system.


By creating a specially-crafted AMHS URI, an attacker may be able to inject arbitrary JavaScript into an AMHS session or access information about other AMHS users.


Apply an update

These issues are addressed in AMHS version Please contact Telos for update availability.

Vendor Information


Telos Affected

Notified:  December 16, 2019 Updated: December 19, 2019



Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

CVSS Metrics

Group Score Vector
Base 6.4 AV:N/AC:L/Au:N/C:P/I:P/A:N
Temporal 5 E:POC/RL:OF/RC:C
Environmental 3.8 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND



This document was written by Will Dormann.

Other Information

CVE IDs: CVE-2019-9537, CVE-2019-9538, CVE-2019-9539, CVE-2019-9540, CVE-2019-9541, CVE-2019-9542
Date Public: 2019-12-19
Date First Published: 2019-12-19
Date Last Updated: 2019-12-19 20:39 UTC
Document Revision: 15

Sponsored by CISA.