Latest zohocorp manageengine applications manager Vulnerabilities

Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
Zohocorp Manageengine Applications Manager<16.5
Zohocorp Manageengine Applications Manager=16.5
Zohocorp Manageengine Applications Manager=16.5-build16500
Zohocorp Manageengine Applications Manager=16.5-build16510
Zohocorp Manageengine Applications Manager=16.5-build16511
Zohocorp Manageengine Applications Manager=16.5-build16520
and 1 more
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
Zohocorp Manageengine Applications Manager<16.3
Zohocorp Manageengine Applications Manager=16.3-build16300
Zohocorp Manageengine Applications Manager=16.3-build16310
Zohocorp Manageengine Applications Manager=16.3-build16320
Zohocorp Manageengine Applications Manager=16.3-build16330
Zohocorp Manageengine Applications Manager=16.3-build16340
and 6 more
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details pag...
Zohocorp Manageengine Applications Manager>=16.0<16.3
Zohocorp Manageengine Applications Manager=15.9-build15990
Zohocorp Manageengine Applications Manager=16.3-build16300
Zohocorp Manageengine Applications Manager=16.3-build16310
Zohocorp Manageengine Applications Manager=16.3-build16320
Zohocorp Manageengine Applications Manager=16.3-build16330
and 1 more
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
Zohocorp Manageengine Applications Manager<16.3
Zohocorp Manageengine Applications Manager=16.3-build16300
Zohocorp Manageengine Applications Manager=16.3-build16310
Zohocorp Manageengine Applications Manager=16.3-build16320
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' func...
Zohocorp Manageengine Applications Manager>=15.0<15.5
Zohocorp Manageengine Applications Manager=15.5
Zohocorp Manageengine Applications Manager=15.5-build15500
Zohocorp Manageengine Applications Manager=15.5-build15510
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
Zohocorp Manageengine Applications Manager=11.0-build11010
Zohocorp Manageengine Applications Manager=11.0-build11020
Zohocorp Manageengine Applications Manager=11.0-build11030
Zohocorp Manageengine Applications Manager=11.0-build11040
Zohocorp Manageengine Applications Manager=11.0-build11100
Zohocorp Manageengine Applications Manager=11.1-build11110
and 151 more
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
Zohocorp Manageengine Applications Manager<14.5
Zohocorp Manageengine Applications Manager=14.5
Zohocorp Manageengine Applications Manager=14.5-build14500
Zohocorp Manageengine Applications Manager=14.5-build14510
Zohocorp Manageengine Applications Manager=14.5-build14520
Zohocorp Manageengine Applications Manager=14.5-build14530
and 1 more
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
Zohocorp Manageengine Applications Manager=15.2-15200
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
Zohocorp Manageengine Applications Manager<15.1
Zohocorp Manageengine Applications Manager=15.1
Zohocorp Manageengine Applications Manager=15.1-15100
Zohocorp Manageengine Applications Manager=15.1-15110
Zohocorp Manageengine Applications Manager=15.1-15120
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
Zohocorp Manageengine Applications Manager<14.9
Zohocorp Manageengine Applications Manager=14.9
Zohocorp Manageengine Applications Manager=14.9-build14900
Zohocorp Manageengine Applications Manager=14.9-build14910
Zohocorp Manageengine Applications Manager=14.9-build14911
Zohocorp Manageengine Applications Manager=14.9-build14930
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
Zohocorp Manageengine Applications Manager=14.0
Zohocorp Manageengine Applications Manager=14.0-build14000
Zohocorp Manageengine Applications Manager=14.0-build14010
Zohocorp Manageengine Applications Manager=14.0-build14020
Zohocorp Manageengine Applications Manager=14.0-build14030
Zohocorp Manageengine Applications Manager=14.0-build14040
and 100 more
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
Zohocorp Manageengine Applications Manager=14.7
Zohocorp Manageengine Applications Manager=14.7-build14700
Zohocorp Manageengine Applications Manager=14.7-build14710
Zohocorp Manageengine Applications Manager=14.7-build14720
Zohocorp Manageengine Applications Manager=14.7-build14730
Zohocorp Manageengine Applications Manager=14.7-build14740
and 4 more
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
Zohocorp Manageengine Applications Manager=14.7
Zohocorp Manageengine Applications Manager=14.7
Zohocorp Manageengine Applications Manager=14.7-build14700
Zohocorp Manageengine Applications Manager=14.7-build14710
Zohocorp Manageengine Applications Manager=14.7-build14720
Zohocorp Manageengine Applications Manager=14.7-build14730
and 1 more
Zohocorp Manageengine Applications Manager=14.7
Zohocorp Manageengine Applications Manager=14.7
Zohocorp Manageengine Applications Manager=14.7-build14700
Zohocorp Manageengine Applications Manager=14.7-build14710
Zohocorp Manageengine Applications Manager=14.7-build14720
Zohocorp Manageengine Applications Manager=14.7-build14730
and 1 more
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
Zohocorp Manageengine Applications Manager<14.6
Zohocorp Manageengine Applications Manager=14.6
Zohocorp Manageengine Applications Manager=14.6-build14680
Zohocorp Manageengine Applications Manager=14.6-build14681
Zohocorp Manageengine Applications Manager=14.6-build14682
Zohocorp Manageengine Applications Manager=14.6-build14683
and 7 more
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
Zohocorp Manageengine Applications Manager<14.0
Zohocorp Manageengine Applications Manager=14.0
Zohocorp Manageengine Applications Manager=14.0-build14000
Zohocorp Manageengine Applications Manager=14.0-build14010
Zohocorp Manageengine Applications Manager=14.0-build14020
Zohocorp Manageengine Applications Manager=14.0-build14030
and 82 more
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
Zohocorp Manageengine Applications Manager<14.0
Zohocorp Manageengine Applications Manager=14.0
Zohocorp Manageengine Applications Manager=14.0-build14000
Zohocorp Manageengine Applications Manager=14.0-build14010
Zohocorp Manageengine Applications Manager=14.0-build14020
Zohocorp Manageengine Applications Manager=14.0-build14030
and 83 more
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
Zohocorp Manageengine Applications Manager<=13.0
Zohocorp Manageengine Applications Manager=14.0
Zohocorp Manageengine Applications Manager=14.0-build14000
Zohocorp Manageengine Applications Manager=14.0-build14010
Zohocorp Manageengine Applications Manager=14.0-build14020
Zohocorp Manageengine Applications Manager=14.0-build14030
and 81 more
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properl...
Zohocorp Manageengine Applications Manager<=11.9
Zohocorp Manageengine It360<=10.5
Zohocorp Manageengine Opmanager>=8<=11.5
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
Zohocorp Manageengine Applications Manager=14.0
Zohocorp Manageengine Applications Manager=14.0-build14000
Zohocorp Manageengine Applications Manager=14.0-build14010
Zohocorp Manageengine Applications Manager=14.0-build14020
Zohocorp Manageengine Applications Manager=14.0-build14030
Zohocorp Manageengine Applications Manager=14.0-build14040
and 55 more
Zohocorp Manageengine Applications Manager=14.3-14360
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
Zohocorp Manageengine Applications Manager<13.7
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
Zohocorp Manageengine Applications Manager<13.7
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a lo...
Zohocorp Manageengine Applications Manager>=12.0<=14.2
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authori...
Zohocorp Manageengine Applications Manager>=12.0<=14.0
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environmen...
Zohocorp Manageengine Applications Manager=12.3
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse ...
Zohocorp Manageengine Applications Manager=13.1-13100
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget...
Zohocorp Manageengine Applications Manager=13.1-13100
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
Zohocorp Manageengine Applications Manager=13.1-13100
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by u...
Zohocorp Manageengine Applications Manager>=12.0<=14.0
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vul...
Zohocorp Manageengine Applications Manager>=11.0<=14.0
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
Zohocorp Manageengine Applications Manager=13.7
Zohocorp Manageengine Applications Manager=13.7-build13700
Zohocorp Manageengine Applications Manager=13.7-build13710
Zohocorp Manageengine Applications Manager=13.7-build13720
Zohocorp Manageengine Applications Manager=13.7-build13730
Zohocorp Manageengine Applications Manager=13.7-build13750
and 4 more
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do...
Zohocorp Manageengine Applications Manager<13.13820
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
Zohocorp Manageengine Applications Manager<13.13820
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem an...
Zohocorp Manageengine Applications Manager=12.0
Zohocorp Manageengine Applications Manager=13.0
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to...
Zohocorp Manageengine Applications Manager=12.0
Zohocorp Manageengine Applications Manager=13.0
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
Zohocorp Manageengine Applications Manager=13.0
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter ...
Zohocorp Manageengine Applications Manager<=13
Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server i...
Zohocorp Manageengine Applications Manager=13

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203