CVE-2019-11361 — Incorrect Authorization in Manageengine Remote Access Plus

Severity
8.8HIGHNVD
EPSS
0.2%
top 55.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 24

Description

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qqm9-7235-jf9v: Zoho ManageEngine Remote Access Plus 10↗2022-05-24
â–¶
CVEList
CVE-2019-11361: Zoho ManageEngine Remote Access Plus 10↗2020-03-19
â–¶
CVE-2019-11361 — Incorrect Authorization | cvebase