Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2020-05-18 CVE-2020-13154 Missing Authorization vulnerability in Zohocorp Manageengine Servicedesk Plus 11.1
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
network
low complexity
zohocorp CWE-862
6.5
2020-05-14 CVE-2019-15083 Cross-site Scripting vulnerability in Zohocorp Manageengine Servicedesk Plus 10.0.0
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator.
network
low complexity
zohocorp CWE-79
6.1
2020-05-08 CVE-2020-11532 Insecure Default Initialization of Resource vulnerability in Zohocorp products
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.
network
low complexity
zohocorp CWE-1188
critical
9.8
2020-05-08 CVE-2020-11531 Path Traversal vulnerability in Zohocorp products
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request.
network
low complexity
zohocorp CWE-22
8.8
2020-05-07 CVE-2020-12116 Path Traversal vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
network
low complexity
zohocorp CWE-22
7.5
2020-05-05 CVE-2020-10859 Path Traversal vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
network
low complexity
zohocorp CWE-22
6.5
2020-04-20 CVE-2020-11946 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Opmanager 12.5
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
network
low complexity
zohocorp CWE-306
7.5
2020-04-04 CVE-2020-11527 Unspecified vulnerability in Zohocorp Manageengine Opmanager
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
network
low complexity
zohocorp
7.5
2020-04-04 CVE-2020-11518 Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
network
low complexity
zohocorp
critical
9.8
2020-03-30 CVE-2020-8509 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
network
low complexity
zohocorp CWE-306
7.5