VendorsZoho Corpmanageengine_applications_manager13.0
Vulnerabilities

Zoho Corp Zohocorp ManageEngine Applications Manager 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2016-9498
ManageEngine Applications Manager 12 and 13, allows unserialization of unsafe Java objects
Published 2018-07-13 · Modified
10.0EPSS 0.212
CVE-2018-13050
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
Published 2018-07-02 · Modified
9.8EPSS 0.398
CVE-2017-16846
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
Published 2017-11-16 · Modified
9.8EPSS 0.166
CVE-2017-16847
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
Published 2017-11-16 · Modified
9.8EPSS 0.166
CVE-2017-16849
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
Published 2017-11-16 · Modified
9.8EPSS 0.166
CVE-2017-16850
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
Published 2017-11-16 · Modified
9.8EPSS 0.166
CVE-2017-16851
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
Published 2017-11-16 · Modified
9.8EPSS 0.166
CVE-2017-16848
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
Published 2017-11-16 · Modified
9.8EPSS 0.151
CVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
Published 2017-11-05 · Modified
9.81 PoCEPSS 0.056
CVE-2017-16542
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
Published 2017-11-05 · Modified
8.81 PoCEPSS 0.055
CVE-2020-28679
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
Published 2022-01-10 · Modified
8.8EPSS 0.025
CVE-2016-9489
ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation and authentication bypass
Published 2018-07-13 · Modified
8.8EPSS 0.017
CVE-2016-9491
ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation due to improper restriction of an XML external entity
Published 2018-07-13 · Modified
6.8EPSS 0.025