10
CVE-2020-24786
- EPSS 6.78%
- Published 31.08.2020 15:15:10
- Last modified 21.11.2024 05:16:04
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.
Data is provided by the National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version <= 5.7
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update-
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5800
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5801
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5802
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5803
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5804
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5805
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5806
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5807
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5808
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5809
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5810
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5811
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5812
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5813
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5814
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5815
Zohocorp ≫ Manageengine Adselfservice Plus Version5.8 Update5816
Zohocorp ≫ Manageengine Exchange Reporter Plus Version <= 5.4
Zohocorp ≫ Manageengine Exchange Reporter Plus Version5.5 Update5500
Zohocorp ≫ Manageengine Exchange Reporter Plus Version5.5 Update5501
Zohocorp ≫ Manageengine Exchange Reporter Plus Version5.5 Update5502
Zohocorp ≫ Manageengine Exchange Reporter Plus Version5.5 Update5503
Zohocorp ≫ Manageengine Exchange Reporter Plus Version5.5 Update5504
Zohocorp ≫ Manageengine Ad360 Version <= 4.1
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4200
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4201
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4202
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4203
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4204
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4205
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4206
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4207
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4208
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4209
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4210
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4212
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4213
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4214
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4215
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4216
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4217
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4219
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4220
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4222
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4223
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4224
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4225
Zohocorp ≫ Manageengine Ad360 Version4.2 Update4227
Zohocorp ≫ Manageengine Datasecurity Plus Version <= 5.0
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6000
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6001
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6002
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6003
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6010
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6011
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6012
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6013
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6020
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6021
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6030
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6031
Zohocorp ≫ Manageengine Datasecurity Plus Version6.0 Update6032
Zohocorp ≫ Manageengine Recovermanager Plus Version <= 5.4
Zohocorp ≫ Manageengine Recovermanager Plus Version6.0 Update6001
Zohocorp ≫ Manageengine Recovermanager Plus Version6.0 Update6003
Zohocorp ≫ Manageengine Recovermanager Plus Version6.0 Update6005
Zohocorp ≫ Manageengine Recovermanager Plus Version6.0 Update6011
Zohocorp ≫ Manageengine Recovermanager Plus Version6.0 Update6016
Zohocorp ≫ Manageengine Eventlog Analyzer Version <= 12.1.2
Zohocorp ≫ Manageengine Eventlog Analyzer Version12.1.3 Update12130
Zohocorp ≫ Manageengine Eventlog Analyzer Version12.1.3 Update12135
Zohocorp ≫ Manageengine Adaudit Plus Version <= 5.1
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6000
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6001
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6002
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6003
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6010
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6030
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6031
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6032
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6033
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6050
Zohocorp ≫ Manageengine Adaudit Plus Version6.0 Update6052
Zohocorp ≫ Manageengine O365 Manager Plus Version <= 4.2
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4300
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4301
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4302
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4303
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4304
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4305
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4306
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4308
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4309
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4310
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4311
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4312
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4316
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4317
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4318
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4319
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4320
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4321
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4322
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4324
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4325
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4327
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4328
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4329
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4330
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4331
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4332
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4333
Zohocorp ≫ Manageengine O365 Manager Plus Version4.3 Update4334
Zohocorp ≫ Manageengine Cloud Security Plus Version <= 4.0
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4100
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4101
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4102
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4103
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4104
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4105
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4106
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4107
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4108
Zohocorp ≫ Manageengine Cloud Security Plus Version4.1 Update4109
Zohocorp ≫ Manageengine Admanager Plus Version <= 6.6
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7000
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7010
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7011
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7020
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7030
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7040
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7041
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7050
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7051
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7052
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7053
Zohocorp ≫ Manageengine Admanager Plus Version7.0 Update7054
Zohocorp ≫ Manageengine Log360 Version <= 5.0
Zohocorp ≫ Manageengine Log360 Version5.1 Update5100
Zohocorp ≫ Manageengine Log360 Version5.1 Update5102
Zohocorp ≫ Manageengine Log360 Version5.1 Update5107
Zohocorp ≫ Manageengine Log360 Version5.1 Update5108
Zohocorp ≫ Manageengine Log360 Version5.1 Update5110
Zohocorp ≫ Manageengine Log360 Version5.1 Update5111
Zohocorp ≫ Manageengine Log360 Version5.1 Update5120
Zohocorp ≫ Manageengine Log360 Version5.1 Update5150
Zohocorp ≫ Manageengine Log360 Version5.1 Update5154
Zohocorp ≫ Manageengine Log360 Version5.1 Update5155
Zohocorp ≫ Manageengine Log360 Version5.1 Update5160
Zohocorp ≫ Manageengine Log360 Version5.1 Update5164
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.78% | 0.909 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.