VendorsZoho Corpmanageengine_assetexplorer6.2.0
Vulnerabilities

Zoho Corp zohocorp ManageEngine Asset Explorer 6.2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-12994
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Published 2019-08-08 · Modified
9.1EPSS 0.044
CVE-2019-14693
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Published 2019-08-08 · Modified
8.5EPSS 0.042
CVE-2018-17596
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
Published 2018-10-02 · Modified
6.1EPSS 0.023