Zohocorp

Manageengine Applications Manager

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 40.06%
  • Veröffentlicht 04.09.2020 15:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:20

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

Exploit
  • EPSS 6.45%
  • Veröffentlicht 13.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:24

Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

Exploit
  • EPSS 83.4%
  • Veröffentlicht 08.02.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 02:18:09

The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers a...

  • EPSS 3.89%
  • Veröffentlicht 06.02.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:35:24

Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

  • EPSS 2.55%
  • Veröffentlicht 10.01.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:48

An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticate...

  • EPSS 5.68%
  • Veröffentlicht 11.12.2019 18:16:19
  • Zuletzt bearbeitet 21.11.2024 04:35:08

Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.

  • EPSS 9.51%
  • Veröffentlicht 11.12.2019 18:16:19
  • Zuletzt bearbeitet 21.11.2024 04:35:07

Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

Exploit
  • EPSS 7.79%
  • Veröffentlicht 16.08.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:03

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM ...

Exploit
  • EPSS 7.79%
  • Veröffentlicht 16.08.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:03

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the se...

Exploit
  • EPSS 3.7%
  • Veröffentlicht 23.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:00

An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser reque...