ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
View the template here CVE-2019-9632.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-9632