5.3

CVE-2019-19799

Exploit

Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14500
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14510
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14520
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14530
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14540
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14560
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14570
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14580
ZohocorpManageengine Applications Manager Version14.5 Updatebuild14590
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.9% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.