Vulnerabilities > CVE-2018-16364 - Deserialization of Untrusted Data vulnerability in Zohocorp Manageengine Applications Manager 13.7

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
zohocorp
CWE-502

Summary

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

Vulnerable Configurations

Part Description Count
Application
Zohocorp
10

Common Weakness Enumeration (CWE)