Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.manageengine.com | product |
https://gitlab.com/eLeN3Re/CVE-2019-19800/ | third party advisory |
https://www.manageengine.com/products/applications_manager/release-notes.html | release notes |