CVE-2020-15533
- EPSS 11.45%
- Veröffentlicht 01.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:42
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
CVE-2020-15521
- EPSS 7.34%
- Veröffentlicht 25.09.2020 07:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:41
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
CVE-2020-15394
- EPSS 31.38%
- Veröffentlicht 25.09.2020 07:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:28
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
CVE-2020-14008
- EPSS 45.04%
- Veröffentlicht 04.09.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:20
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
CVE-2019-19799
- EPSS 6.9%
- Veröffentlicht 13.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:24
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
CVE-2014-7863
- EPSS 88.87%
- Veröffentlicht 08.02.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 02:18:09
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers a...
CVE-2019-19800
- EPSS 9.89%
- Veröffentlicht 06.02.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:35:24
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
- EPSS 0.25%
- Veröffentlicht 10.01.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:48
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticate...
CVE-2019-19650
- EPSS 7.39%
- Veröffentlicht 11.12.2019 18:16:19
- Zuletzt bearbeitet 21.11.2024 04:35:08
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
CVE-2019-19649
- EPSS 61.06%
- Veröffentlicht 11.12.2019 18:16:19
- Zuletzt bearbeitet 21.11.2024 04:35:07
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.