Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2021-44652 Unspecified vulnerability in Zohocorp Manageengine O365 Manager Plus
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
local
low complexity
zohocorp
7.8
2022-01-12 CVE-2021-44650 Unspecified vulnerability in Zohocorp Manageengine M365 Manager Plus 4.4
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
network
low complexity
zohocorp
7.2
2022-01-10 CVE-2020-28679 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
network
low complexity
zohocorp CWE-89
8.8
2022-01-10 CVE-2021-46164 Unspecified vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
network
low complexity
zohocorp
8.8
2022-01-10 CVE-2021-46165 Unspecified vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
local
low complexity
zohocorp
7.8
2022-01-10 CVE-2021-46166 Information Exposure vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
network
low complexity
zohocorp CWE-200
6.5
2022-01-03 CVE-2021-20147 Information Exposure Through Discrepancy vulnerability in Zohocorp Manageengine Adselfservice Plus
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI.
network
low complexity
zohocorp CWE-203
5.3
2022-01-03 CVE-2021-20148 Files or Directories Accessible to External Parties vulnerability in Zohocorp Manageengine Adselfservice Plus
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name.
network
low complexity
zohocorp CWE-552
4.3
2021-12-23 CVE-2021-44526 Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
network
low complexity
zohocorp
critical
9.8
2021-12-20 CVE-2021-44525 Improper Authentication vulnerability in Zohocorp Manageengine Pam360
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
network
low complexity
zohocorp CWE-287
critical
9.8