CWE
611
Advisory Published
Updated

CVE-2018-20664: XEE

First published: Thu Jan 03 2019(Updated: )

Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Adselfservice Plus=5.7-4500
Zohocorp Manageengine Adselfservice Plus=5.7-5032
Zohocorp Manageengine Adselfservice Plus=5.7-5040
Zohocorp Manageengine Adselfservice Plus=5.7-5041
Zohocorp Manageengine Adselfservice Plus=5.7-5100
Zohocorp Manageengine Adselfservice Plus=5.7-5101
Zohocorp Manageengine Adselfservice Plus=5.7-5102
Zohocorp Manageengine Adselfservice Plus=5.7-5103
Zohocorp Manageengine Adselfservice Plus=5.7-5104
Zohocorp Manageengine Adselfservice Plus=5.7-5105
Zohocorp Manageengine Adselfservice Plus=5.7-5106
Zohocorp Manageengine Adselfservice Plus=5.7-5107
Zohocorp Manageengine Adselfservice Plus=5.7-5108
Zohocorp Manageengine Adselfservice Plus=5.7-5109
Zohocorp Manageengine Adselfservice Plus=5.7-5110
Zohocorp Manageengine Adselfservice Plus=5.7-5111
Zohocorp Manageengine Adselfservice Plus=5.7-5112
Zohocorp Manageengine Adselfservice Plus=5.7-5113
Zohocorp Manageengine Adselfservice Plus=5.7-5114
Zohocorp Manageengine Adselfservice Plus=5.7-5115
Zohocorp Manageengine Adselfservice Plus=5.7-5116
Zohocorp Manageengine Adselfservice Plus=5.7-5200
Zohocorp Manageengine Adselfservice Plus=5.7-5201
Zohocorp Manageengine Adselfservice Plus=5.7-5202
Zohocorp Manageengine Adselfservice Plus=5.7-5203
Zohocorp Manageengine Adselfservice Plus=5.7-5204
Zohocorp Manageengine Adselfservice Plus=5.7-5205
Zohocorp Manageengine Adselfservice Plus=5.7-5206
Zohocorp Manageengine Adselfservice Plus=5.7-5207
Zohocorp Manageengine Adselfservice Plus=5.7-5300
Zohocorp Manageengine Adselfservice Plus=5.7-5301
Zohocorp Manageengine Adselfservice Plus=5.7-5302
Zohocorp Manageengine Adselfservice Plus=5.7-5303
Zohocorp Manageengine Adselfservice Plus=5.7-5304
Zohocorp Manageengine Adselfservice Plus=5.7-5305
Zohocorp Manageengine Adselfservice Plus=5.7-5306
Zohocorp Manageengine Adselfservice Plus=5.7-5307
Zohocorp Manageengine Adselfservice Plus=5.7-5308
Zohocorp Manageengine Adselfservice Plus=5.7-5309
Zohocorp Manageengine Adselfservice Plus=5.7-5310
Zohocorp Manageengine Adselfservice Plus=5.7-5311
Zohocorp Manageengine Adselfservice Plus=5.7-5312
Zohocorp Manageengine Adselfservice Plus=5.7-5313
Zohocorp Manageengine Adselfservice Plus=5.7-5314
Zohocorp Manageengine Adselfservice Plus=5.7-5315
Zohocorp Manageengine Adselfservice Plus=5.7-5316
Zohocorp Manageengine Adselfservice Plus=5.7-5317
Zohocorp Manageengine Adselfservice Plus=5.7-5318
Zohocorp Manageengine Adselfservice Plus=5.7-5319
Zohocorp Manageengine Adselfservice Plus=5.7-5320
Zohocorp Manageengine Adselfservice Plus=5.7-5321
Zohocorp Manageengine Adselfservice Plus=5.7-5322
Zohocorp Manageengine Adselfservice Plus=5.7-5323
Zohocorp Manageengine Adselfservice Plus=5.7-5324
Zohocorp Manageengine Adselfservice Plus=5.7-5325
Zohocorp Manageengine Adselfservice Plus=5.7-5326
Zohocorp Manageengine Adselfservice Plus=5.7-5327
Zohocorp Manageengine Adselfservice Plus=5.7-5328
Zohocorp Manageengine Adselfservice Plus=5.7-5329
Zohocorp Manageengine Adselfservice Plus=5.7-5330
Zohocorp Manageengine Adselfservice Plus=5.7-5400
Zohocorp Manageengine Adselfservice Plus=5.7-5500
Zohocorp Manageengine Adselfservice Plus=5.7-5501
Zohocorp Manageengine Adselfservice Plus=5.7-5502
Zohocorp Manageengine Adselfservice Plus=5.7-5503
Zohocorp Manageengine Adselfservice Plus=5.7-5504
Zohocorp Manageengine Adselfservice Plus=5.7-5505
Zohocorp Manageengine Adselfservice Plus=5.7-5506
Zohocorp Manageengine Adselfservice Plus=5.7-5507
Zohocorp Manageengine Adselfservice Plus=5.7-5508
Zohocorp Manageengine Adselfservice Plus=5.7-5509
Zohocorp Manageengine Adselfservice Plus=5.7-5510
Zohocorp Manageengine Adselfservice Plus=5.7-5511
Zohocorp Manageengine Adselfservice Plus=5.7-5512
Zohocorp Manageengine Adselfservice Plus=5.7-5513
Zohocorp Manageengine Adselfservice Plus=5.7-5514
Zohocorp Manageengine Adselfservice Plus=5.7-5515
Zohocorp Manageengine Adselfservice Plus=5.7-5516
Zohocorp Manageengine Adselfservice Plus=5.7-5517
Zohocorp Manageengine Adselfservice Plus=5.7-5518
Zohocorp Manageengine Adselfservice Plus=5.7-5519
Zohocorp Manageengine Adselfservice Plus=5.7-5520
Zohocorp Manageengine Adselfservice Plus=5.7-5521
Zohocorp Manageengine Adselfservice Plus=5.7-5600
Zohocorp Manageengine Adselfservice Plus=5.7-5601
Zohocorp Manageengine Adselfservice Plus=5.7-5602
Zohocorp Manageengine Adselfservice Plus=5.7-5603
Zohocorp Manageengine Adselfservice Plus=5.7-5604
Zohocorp Manageengine Adselfservice Plus=5.7-5605
Zohocorp Manageengine Adselfservice Plus=5.7-5606
Zohocorp Manageengine Adselfservice Plus=5.7-5607
Zohocorp Manageengine Adselfservice Plus=5.7-5700

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2018-20664 vulnerability about?

    Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

  • How severe is CVE-2018-20664?

    The severity of CVE-2018-20664 is rated as critical with a CVSS score of 9.8.

  • Which software versions are affected by CVE-2018-20664?

    Zoho ManageEngine ADSelfService Plus versions 5.7-4500 to 5.7-5700 are affected by CVE-2018-20664.

  • Where can I find more information about CVE-2018-20664 vulnerability?

    You can find more information about CVE-2018-20664 vulnerability at excellium-services.com and manageengine.com.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203