CVE-2019-19650: SQL Injection
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Zoho ManageEngine Applications Manager?
The vulnerability ID for Zoho ManageEngine Applications Manager is CVE-2019-19650.
What is the severity of CVE-2019-19650?
The severity of CVE-2019-19650 is high, with a severity value of 8.8.
What is the description of CVE-2019-19650?
CVE-2019-19650 is a vulnerability in Zoho ManageEngine Applications Manager that allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
How does CVE-2019-19650 affect Zoho ManageEngine Applications Manager?
CVE-2019-19650 affects Zoho ManageEngine Applications Manager versions up to 13.7.
Is there a fix available for CVE-2019-19650?
Yes, a fix for CVE-2019-19650 is available. Please refer to the release notes for Zoho ManageEngine Applications Manager for more information on the fix.