CVE-2019-19649: SQL Injection
Published Dec 11, 2019
·Updated
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
Affected Software
1 affected component
ZohoCorp ManageEngine Applications Manager<13.7
Event History
Dec 11, 2019
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19649?
The severity of CVE-2019-19649 is critical with a severity value of 9.8.
2
How does CVE-2019-19649 affect Zoho ManageEngine Applications Manager?
CVE-2019-19649 affects Zoho ManageEngine Applications Manager before version 13.7.
3
What is the vulnerability type of CVE-2019-19649?
The vulnerability type of CVE-2019-19649 is SQL injection.
4
How can an attacker exploit CVE-2019-19649?
An attacker can exploit CVE-2019-19649 by sending a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter.
5
Is there a patch available for CVE-2019-19649?
Yes, a patch is available for CVE-2019-19649. Users should update to version 13.7 or later of Zoho ManageEngine Applications Manager.