CVE-2014-9371Improper Input Validation in Manageengine Desktop Central

Severity
10.0CRITICALNVD
EPSS
10.2%
top 6.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 17

Description

The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6cwm-9xcg-xhpj: The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object2022-05-17
CVEList
CVE-2014-9371: The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object2014-12-16
CVE-2014-9371 — Improper Input Validation | cvebase