CVE-2023-28340: XEE
Published Apr 11, 2023
·Updated
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
Affected Software
4 affected components
ZohoCorp ManageEngine Applications Manager<16.3
ZohoCorp ManageEngine Applications Manager=16.3-build16300
ZohoCorp ManageEngine Applications Manager=16.3-build16310
ZohoCorp ManageEngine Applications Manager=16.3-build16320
Remediation
Event History
Apr 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-28340.
2
What is the severity of CVE-2023-28340?
CVE-2023-28340 has a severity rating of 6.5 (medium).
3
What type of attack does CVE-2023-28340 allow?
CVE-2023-28340 allows an admin user to conduct an XXE attack.
4
Which software is affected by CVE-2023-28340?
Zoho ManageEngine Applications Manager version 16.3 through 16320 is affected by CVE-2023-28340.
5
How can I fix CVE-2023-28340?
To fix CVE-2023-28340, update Zoho ManageEngine Applications Manager to a version that is not affected by this vulnerability.