7.5

CVE-2020-10816

Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14700
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14710
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14720
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14730
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14740
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14750
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14760
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14770
ZohocorpManageengine Applications Manager Version14.7 Updatebuild14780
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 25.01% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.