VendorsZoho Corpmanageengine_admanager_plus7.1
Vulnerabilities

Zoho Corp ManageEngine ADManager Plus 7.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Published 2023-01-18 · Analyzed
9.8KEVEPSS 0.998
CVE-2021-37539
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
Published 2021-09-27 · Modified
9.8EPSS 0.929
CVE-2021-37926
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.736
CVE-2021-37918
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.736
CVE-2021-37924
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.110
CVE-2021-37923
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.110
CVE-2021-37919
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.110
CVE-2021-37920
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.110
CVE-2021-37921
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.110
CVE-2021-37925
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
Published 2021-09-22 · Modified
9.8EPSS 0.105
CVE-2021-37930
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.095
CVE-2021-37929
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.095
CVE-2021-37928
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.095
CVE-2021-37931
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.095
CVE-2021-37761
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
Published 2021-09-27 · Modified
9.8EPSS 0.095
CVE-2021-37762
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
Published 2021-10-07 · Modified
9.8EPSS 0.081
CVE-2021-42002
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
Published 2021-11-11 · Modified
9.8EPSS 0.075
CVE-2021-33911
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
Published 2021-07-17 · Modified
9.8EPSS 0.053
CVE-2021-38298
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
Published 2021-10-07 · Modified
9.8EPSS 0.026
CVE-2021-37927
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
Published 2021-09-22 · Modified
9.8EPSS 0.022
CVE-2021-20130
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
Published 2021-10-13 · Modified
8.8EPSS 0.325
CVE-2021-20131
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
Published 2021-10-13 · Modified
8.8EPSS 0.168
CVE-2022-29457
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
Published 2022-04-18 · Modified
8.81 PoCEPSS 0.079
CVE-2024-24409
Privilege Escalation
Published 2024-11-08 · Analyzed
8.81 PoCEPSS 0.062
CVE-2021-37741
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
Published 2021-09-21 · Modified
8.8EPSS 0.027
CVE-2023-29084
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
Published 2023-04-13 · Modified
7.2EPSS 0.982
CVE-2022-42904
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
Published 2022-11-18 · Modified
7.2EPSS 0.831
CVE-2023-31492
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
Published 2023-08-17 · Modified
6.5EPSS 0.079
CVE-2021-36772
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
Published 2021-07-17 · Modified
6.1EPSS 0.009
CVE-2021-36771
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
Published 2021-07-17 · Modified
6.1EPSS 0.009
CVE-2021-37922
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
Published 2021-10-07 · Modified
5.3EPSS 0.023
CVE-2023-35786
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
Published 2023-07-05 · Modified
4.9EPSS 0.030