Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://gitlab.com/eLeN3Re/cve-2019-19799 | third party advisory exploit |
https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2019-19799.html | vendor advisory |