CVE-2019-19800: Zohocorp ManageEngine Applications Manager

Medium severity, CVSS 5.3. EPSS: 3.9% chance of exploitation in the next 30 days.

Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

Affected products

  • Zohocorp ManageEngine Applications Manager: version 14.0 only

Published 2020-02-06. Last modified 2026-06-17.