Vulnerabilities > Zohocorp > Manageengine Remote Access Plus > 10.0.258

DATE CVE VULNERABILITY TITLE RISK
2020-03-19 CVE-2019-11361 Incorrect Authorization vulnerability in Zohocorp Manageengine Remote Access Plus 10.0.258
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
network
low complexity
zohocorp CWE-863
6.5
2020-01-31 CVE-2020-8422 Insufficiently Protected Credentials vulnerability in Zohocorp Manageengine Remote Access Plus
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450.
network
low complexity
zohocorp CWE-522
4.0