CVE-2019-19475 describes a privilege escalation vulnerability in ManageEngine Applications Manager 14, specifically build 14360, stemming from insecure file permissions within its integrated PostgreSQL database. Authenticated users can exploit this flaw to modify PostgreSQL configurations, enabling arbitrary command execution and ultimately gaining full system privileges. Rated with a CVSS score of 8.8 (High), this vulnerability allows for remote exploitation with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_applications_manager:14.3:14360:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.