Critical severity9.8NVD Advisory· Published Dec 11, 2019· Updated Jun 17, 2026
CVE-2019-19649
CVE-2019-19649
Description
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*Range: <13.7
- Zoho/ManageEngine Applications Managerdescription
- Range: <13620
Patches
Vulnerability mechanics
References
1- www.manageengine.com/products/applications_manager/release-notes.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.