CVE-2019-19799

Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:-:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14500:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14510:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14520:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14530:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14540:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14560:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14570:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14580:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.5:build14590:*:*:*:*:*:*

History

31 Mar 2022, 18:18

Type Values Removed Values Added
References (CONFIRM) https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2019-19799.html - (CONFIRM) https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2019-19799.html - Vendor Advisory
CWE CWE-200 CWE-306

Information

Published : 2020-03-13 17:15

Updated : 2024-02-04 21:00


NVD link : CVE-2019-19799

Mitre link : CVE-2019-19799

CVE.ORG link : CVE-2019-19799


JSON object : View

Products Affected

zohocorp

  • manageengine_applications_manager
CWE
CWE-306

Missing Authentication for Critical Function