First published: Thu Aug 08 2019(Updated: )
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Assetexplorer | =6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12994 is critical with a score of 9.1.
Server Side Request Forgery (SSRF) occurs when an attacker can make a server perform unintended requests to internal resources.
You can check if your version of Zoho ManageEngine AssetExplorer is affected by CVE-2019-12994 by verifying if it is version 6.2.0.
There are no known fixes or patches available for CVE-2019-12994 at this time.
CWE-918 refers to Server Side Request Forgery (SSRF), which is the type of vulnerability present in CVE-2019-12994.