Vulnerabilities > Zohocorp > Manageengine Assetexplorer > 1.0.34

DATE CVE VULNERABILITY TITLE RISK
2021-07-19 CVE-2021-20110 Integer Overflow or Wraparound vulnerability in Zohocorp Manageengine Assetexplorer 1.0.34
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address.
network
low complexity
zohocorp CWE-190
critical
9.8
2019-08-08 CVE-2019-12959 Server-Side Request Forgery (SSRF) vulnerability in Zohocorp Manageengine Assetexplorer
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
network
low complexity
zohocorp CWE-918
8.8