Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.Referenceshttps://www.manageengine.com/products/applications_manager/release-notes.htmlhttps://gitlab.com/eLeN3Re/CVE-2019-19650