Vulnerability Details CVE-2019-12994
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.036
EPSS Ranking 87.3%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.5
Products affected by CVE-2019-12994
-
cpe:2.3:a:zohocorp:manageengine_assetexplorer:6.2.0