Did you get a satisfactory explanation of why it was not a vulnerability?
Or did you just take the manager's word for it?
A manager who might lose his job if there was a real security breach?
This is the mindset which this thread is about.
Should I go public with the information? Then I’d be assured they’d fix it right away.
I can see someone else has already gone here. About what I would say as well, but with the following addition... You actually believed a manager about this?!!! Most managers I have worked for have absolutely no clue about the real work - only how to delegate responsibility to someone who does know the ins and outs of a certain work station’s function or area of expertise. I have yet to see a manager be able to accomplish the work of their delegated employee, let alone explain it properly in all my 26 years of working in several industries.