CVE-2019-12959: SSRF
Published Aug 8, 2019
·Updated
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
Affected Software
1 affected component
ZohoCorp Manageengine Assetexplorer<6.2.0
Event History
Aug 8, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12959?
CVE-2019-12959 is a Server Side Request Forgery (SSRF) vulnerability that exists in Zoho ManageEngine AssetExplorer 6.2.0 and earlier versions.
2
How severe is CVE-2019-12959?
CVE-2019-12959 has a severity score of 8.8 (High).
3
Which software versions are affected by CVE-2019-12959?
Zoho ManageEngine AssetExplorer versions up to and including 6.2.0 are affected by CVE-2019-12959.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-12959?
The CWE ID for CVE-2019-12959 is CWE-918.
5
How can I mitigate CVE-2019-12959?
To mitigate CVE-2019-12959, it is recommended to update Zoho ManageEngine AssetExplorer to a version later than 6.2.0.