Vulnerabilities > Zohocorp > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-08 CVE-2019-14693 XXE vulnerability in Zohocorp Manageengine Assetexplorer 6.2.0
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data.
network
low complexity
zohocorp CWE-611
8.1
2019-08-08 CVE-2019-12959 Server-Side Request Forgery (SSRF) vulnerability in Zohocorp Manageengine Assetexplorer
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
network
low complexity
zohocorp CWE-918
8.8
2019-07-17 CVE-2019-12876 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp products
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
local
low complexity
zohocorp CWE-732
7.3
2019-06-18 CVE-2019-12133 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp products
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders.
local
low complexity
zohocorp CWE-732
7.8
2019-05-23 CVE-2017-11559 SQL Injection vulnerability in Zohocorp Manageengine Opmanager 12.2
An issue was discovered in ZOHO ManageEngine OpManager 12.2.
network
low complexity
zohocorp CWE-89
7.5
2019-05-23 CVE-2017-11740 Improper Input Validation vulnerability in Zohocorp Manageengine Applications Manager 13.1
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm.
network
low complexity
zohocorp CWE-20
8.8
2019-05-23 CVE-2017-11738 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager 13.1
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
network
high complexity
zohocorp CWE-89
8.1
2019-04-30 CVE-2018-19374 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp Manageengine Admanager Plus 6.6
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
local
high complexity
zohocorp CWE-732
7.0
2019-04-24 CVE-2019-10008 Session Fixation vulnerability in Zohocorp Servicedesk Plus 9.3
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
network
low complexity
zohocorp CWE-384
8.8
2019-03-25 CVE-2017-9362 XXE vulnerability in Zohocorp Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
network
low complexity
zohocorp CWE-611
8.8