Vulnerabilities > Zohocorp > Manageengine Opmanager

DATE CVE VULNERABILITY TITLE RISK
2020-04-20 CVE-2020-11946 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Opmanager 12.5
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
network
low complexity
zohocorp CWE-306
7.5
2020-04-04 CVE-2020-11527 Unspecified vulnerability in Zohocorp Manageengine Opmanager
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
network
low complexity
zohocorp
7.5
2020-03-13 CVE-2020-10541 Unspecified vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request.
network
low complexity
zohocorp
critical
9.8
2020-02-08 CVE-2014-7863 Information Exposure vulnerability in Zohocorp products
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
network
low complexity
zohocorp CWE-200
7.5
2019-11-21 CVE-2019-17421 Incorrect Default Permissions vulnerability in Zohocorp products
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
local
low complexity
zohocorp CWE-276
7.8
2019-10-15 CVE-2019-17602 SQL Injection vulnerability in Zohocorp Manageengine Opmanager
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089.
network
low complexity
zohocorp CWE-89
critical
9.8
2019-08-16 CVE-2019-15106 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Opmanager
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310.
network
low complexity
zohocorp CWE-306
critical
9.8
2019-06-18 CVE-2019-12133 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp products
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders.
local
low complexity
zohocorp CWE-732
7.8
2019-05-23 CVE-2017-11560 Cross-site Scripting vulnerability in Zohocorp Manageengine Opmanager 12.2
An issue was discovered in ZOHO ManageEngine OpManager 12.2.
network
low complexity
zohocorp CWE-79
5.4
2019-05-23 CVE-2017-11559 SQL Injection vulnerability in Zohocorp Manageengine Opmanager 12.2
An issue was discovered in ZOHO ManageEngine OpManager 12.2.
network
low complexity
zohocorp CWE-89
7.5