Zohocorp Manageengine Applications Manager vulnerabilities

57 known vulnerabilities affecting zohocorp/manageengine_applications_manager.

Total CVEs
57
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH19MEDIUM19

Vulnerabilities

Page 3 of 3
CVE-2018-15168CRITICALCVSS 9.8fixed in 13.138202018-08-08
CVE-2018-15168 [CRITICAL] CWE-89 CVE-2018-15168: A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 1 A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
nvd
CVE-2018-15169MEDIUMCVSS 6.1fixed in 13.138202018-08-08
CVE-2018-15169 [MEDIUM] CWE-79 CVE-2018-15169: A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 be A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
nvd
CVE-2016-9498CRITICALCVSS 9.8v12.0v13.02018-07-13
CVE-2016-9498 [CRITICAL] CWE-502 CVE-2016-9498: ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Jav ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of
nvd
CVE-2016-9489HIGHCVSS 8.8v12.0v13.02018-07-13
CVE-2016-9489 [HIGH] CWE-269 CVE-2016-9489: In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.
nvd
CVE-2016-9491MEDIUMCVSS 4.9v12.0v13.02018-07-13
CVE-2016-9491 [MEDIUM] CWE-611 CVE-2016-9491: ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administra
nvd
CVE-2018-13050CRITICALCVSS 9.8v13.02018-07-02
CVE-2018-13050 [CRITICAL] CWE-89 CVE-2018-13050: A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 138 A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
nvd
CVE-2018-12996MEDIUMCVSS 6.1≤ 132018-06-29
CVE-2018-12996 [MEDIUM] CWE-79 CVE-2018-12996: A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager befor A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
nvd
CVE-2018-11808CRITICALCVSS 9.1v132018-06-06
CVE-2018-11808 [CRITICAL] CWE-20 CVE-2018-11808: Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Versio Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.
nvd
CVE-2018-7890CRITICALCVSS 9.8PoCfixed in 13.62018-03-08
CVE-2018-7890 [CRITICAL] CWE-78 CVE-2018-7890: A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 ( A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the
nvd
CVE-2017-16850CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16850 [CRITICAL] CWE-89 CVE-2017-16850: Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresou Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
nvd
CVE-2017-16851CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16851 [CRITICAL] CWE-89 CVE-2017-16851: Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
nvd
CVE-2017-16846CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16846 [CRITICAL] CWE-89 CVE-2017-16846: Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApp Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
nvd
CVE-2017-16848CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16848 [CRITICAL] CWE-89 CVE-2017-16848: Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
nvd
CVE-2017-16847CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16847 [CRITICAL] CWE-89 CVE-2017-16847: Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresou Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
nvd
CVE-2017-16849CRITICALCVSS 9.8v13.02017-11-16
CVE-2017-16849 [CRITICAL] CWE-89 CVE-2017-16849: Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
nvd
CVE-2017-16543CRITICALCVSS 9.8PoCv13.02017-11-05
CVE-2017-16543 [CRITICAL] CWE-89 CVE-2017-16543: Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView. Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
nvd
CVE-2017-16542HIGHCVSS 8.8PoCv13.02017-11-05
CVE-2017-16542 [HIGH] CWE-89 CVE-2017-16542: Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injectio Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
nvd