Vulnerabilities > Zohocorp > Manageengine Analytics Plus > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-15 CVE-2020-21641 XXE vulnerability in Zohocorp Manageengine Analytics Plus
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.
network
low complexity
zohocorp CWE-611
7.5
2019-06-18 CVE-2019-12133 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp products
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders.
local
low complexity
zohocorp CWE-732
7.8