VendorsZoho Corpmanageengine_applications_manager14.0
Vulnerabilities

Zoho Corp Zohocorp ManageEngine Applications Manager 14.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-27995
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
Published 2020-10-29 · Modified
9.8EPSS 0.088
CVE-2020-15394
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
Published 2020-09-25 · Modified
9.8EPSS 0.079
CVE-2020-27733
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
Published 2021-01-19 · Modified
8.8EPSS 0.088
CVE-2020-28679
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
Published 2022-01-10 · Modified
8.8EPSS 0.025
CVE-2020-14008
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
Published 2020-09-04 · Modified
7.21 PoCEPSS 0.375
CVE-2020-15521
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
Published 2020-09-25 · Modified
6.1EPSS 0.017
CVE-2019-19800
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
Published 2020-02-06 · Modified
5.3EPSS 0.039