Zohocorp
Zohocorp Manageengine Analytics Plus: vulnerabilidades y CVE
Zohocorp Manageengine Analytics Plus tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses2
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-47966 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 ene 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8324 | Crítica (9.8) | 1.7% | — | 11 nov 2025 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration. |
| CVE-2025-9428 | Alta (8.8) | 27% | — | 21 oct 2025 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. |
| CVE-2025-1724 | Alta (7.4) | 1.3% | — | 17 mar 2025 | Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token. |
| CVE-2024-52323 | Alta (8.1) | 1.5% | — | 27 nov 2024 | Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account. |
| CVE-2024-9100 | Media (6.5) | 0.48% | — | 3 oct 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. |
| CVE-2023-6105 | Media (5.5) | 0.69% | — | 15 nov 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product… |
| CVE-2022-47966 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 ene 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
| CVE-2020-21642 | Crítica (9.8) | 7.0% | — | 15 ago 2022 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code. |
| CVE-2020-21641 | Alta (7.5) | 3.9% | — | 15 ago 2022 | Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license… |
| CVE-2019-12133 | Alta (7.8) | 1.7% | — | 18 jun 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Adaudit Plus · 53Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Exchange Reporter Plus · 28Manageengine Assetexplorer · 26Manageengine Servicedesk Plus MSP · 26