CVE-2019-19475
Summary
| CVE | CVE-2019-19475 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-10 22:15:00 UTC |
| Updated | 2023-02-01 17:04:00 UTC |
| Description | An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zohocorp | Manageengine Applications Manager | 14.3 | 14360 | All | All |
| Application | Zohocorp | Manageengine Applications Manager | 14.3 | 14360 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Updates - CVE Details - CVE-2019-19475| ManageEngine Applications Manager | CONFIRM | www.manageengine.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.