VendorsZoho Corpmanageengine_applications_manager14.7
Vulnerabilities

Zoho Corp Zohocorp ManageEngine Applications Manager 14.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-15533
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
Published 2020-10-01 · Modified
9.8EPSS 0.042
CVE-2020-15927
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
Published 2020-10-06 · Modified
8.8EPSS 0.433
CVE-2020-16267
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
Published 2020-10-06 · Modified
8.8EPSS 0.433
CVE-2020-10816
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
Published 2020-10-08 · Modified
7.5EPSS 0.048