CVE-2019-12994
9.1
CRITICAL · CVSS 3.0 · EPSS 4.4% (pctl 91)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.39% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-918 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-08-08 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zohocorp | manageengine assetexplorer |
References
→ the Explorer · watch your stack · NVD