Zohocorp Manageengine Adaudit Plus vulnerabilities

52 known vulnerabilities affecting zohocorp/manageengine_adaudit_plus.

Total CVEs
52
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH38MEDIUM5LOW1

Vulnerabilities

Page 2 of 3
CVE-2024-5487HIGHCVSS 8.8fixed in 8.1v8.12024-08-12
CVE-2024-5487 [HIGH] CWE-89 CVE-2024-5487: Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
nvd
CVE-2024-5527HIGHCVSS 8.8fixed in 8.1v8.12024-08-12
CVE-2024-5527 [HIGH] CWE-89 CVE-2024-5527: Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.
nvd
CVE-2024-36035HIGHCVSS 8.8fixed in 8.0v8.02024-08-12
CVE-2024-36035 [HIGH] CWE-89 CVE-2024-36035: Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
nvd
CVE-2024-36518MEDIUMCVSS 5.4fixed in 8.1v8.12024-08-12
CVE-2024-36518 [HIGH] CWE-89 CVE-2024-36518: Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
nvd
CVE-2024-36036MEDIUMCVSS 4.2fixed in 7.2v7.22024-05-27
CVE-2024-36036 [MEDIUM] CWE-862 CVE-2024-36036: Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.
nvd
CVE-2024-36037MEDIUMCVSS 5.5fixed in 7.2v7.22024-05-27
CVE-2024-36037 [MEDIUM] CWE-863 CVE-2024-36037: Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
nvd
CVE-2024-21791HIGHCVSS 7.2fixed in 7.2v7.22024-05-22
CVE-2024-21791 [MEDIUM] CWE-89 CVE-2024-21791: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
nvd
CVE-2023-49335HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49335 [HIGH] CWE-89 CVE-2023-49335: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server de Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
nvd
CVE-2023-49334HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49334 [HIGH] CWE-89 CVE-2023-49334: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summa Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.
nvd
CVE-2023-49332HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49332 [HIGH] CWE-89 CVE-2023-49332: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
nvd
CVE-2023-49331HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49331 [HIGH] CWE-89 CVE-2023-49331: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports sea Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
nvd
CVE-2023-49330HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49330 [HIGH] CWE-89 CVE-2023-49330: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate repo Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.
nvd
CVE-2023-49333HIGHCVSS 8.8fixed in 7.2v7.22024-05-20
CVE-2023-49333 [HIGH] CWE-89 CVE-2023-49333: Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph featu Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.
nvd
CVE-2023-48793CRITICALCVSS 9.8fixed in 7.2v7.22024-02-02
CVE-2023-48793 [CRITICAL] CWE-89 CVE-2023-48793: Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
nvd
CVE-2023-48792CRITICALCVSS 9.8fixed in 7.2v7.22024-02-02
CVE-2023-48792 [CRITICAL] CWE-89 CVE-2023-48792: Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export opti Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
nvd
CVE-2024-0253HIGHCVSS 8.8fixed in 7.2v7.22024-02-02
CVE-2024-0253 [HIGH] CWE-89 CVE-2024-0253: ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
nvd
CVE-2024-0269HIGHCVSS 8.8fixed in 7.2v7.22024-02-02
CVE-2024-0269 [HIGH] CWE-89 CVE-2024-0269: ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.
nvd
CVE-2023-50785LOWCVSS 2.7v7.22024-01-25
CVE-2023-50785 [LOW] CWE-22 CVE-2023-50785: Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
nvd
CVE-2023-6105MEDIUMCVSS 5.5fixed in 7.2v7.22023-11-15
CVE-2023-6105 [MEDIUM] CWE-200 CVE-2023-6105: An information disclosure vulnerability exists in multiple ManageEngine products that can result in An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine pr
nvd
CVE-2023-35785HIGHCVSS 8.1fixed in 7.2v7.22023-08-28
CVE-2023-35785 [HIGH] CWE-287 CVE-2023-35785: Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManag Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360
nvd
Zohocorp Manageengine Adaudit Plus vulnerabilities | cvebase