« Volver al listado

Zohocorp

Zohocorp Manageengine Applications Manager: vulnerabilidades y CVE

Zohocorp Manageengine Applications Manager tiene 59 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 19 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE59
Últimos 12 meses5
Críticas19
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86681Alta (7.6)0.46%—23 sept 2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors…
CVE-2026-86678Alta (8.8)0.68%—23 sept 2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
CVE-2025-9787Media (6.1)1.1%—18 dic 2025
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
CVE-2025-9223Alta (8.8)4.2%—11 nov 2025
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
CVE-2025-6239Media (6.5)0.96%—21 oct 2025
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
CVE-2025-27930Media (5.4)0.40%—23 jul 2025
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
CVE-2024-41140Media (6.5)0.93%—29 ene 2025
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
CVE-2024-5678Media (4.7)2.5%—1 ago 2024
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
CVE-2023-38333Media (6.1)2.3%—10 ago 2023
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
CVE-2023-29442Media (6.1)9.4%—26 abr 2023
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
CVE-2023-28341Media (6.1)99%—11 abr 2023
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
CVE-2023-28340Media (6.5)3.2%—11 abr 2023
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
CVE-2022-23050Alta (7.2)4.9%—24 may 2022
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
CVE-2020-28679Alta (8.8)2.5%—10 ene 2022
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
CVE-2020-24743Crítica (9.8)2.8%—3 nov 2021
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
CVE-2021-35512Media (6.5)1.6%—21 oct 2021
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
CVE-2021-31813Media (5.4)78%—1 jul 2021
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
CVE-2020-35765Alta (8.8)27%—5 feb 2021
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
CVE-2020-27733Alta (8.8)8.8%—19 ene 2021
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
CVE-2020-27995Crítica (9.8)8.8%—29 oct 2020
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
CVE-2020-10816Alta (7.5)4.8%—8 oct 2020
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
CVE-2020-16267Alta (8.8)41%—6 oct 2020
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
CVE-2020-15927Alta (8.8)41%—6 oct 2020
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
CVE-2020-15533Crítica (9.8)4.2%—1 oct 2020
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
CVE-2020-15521Media (6.1)1.7%—25 sept 2020
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
CVE-2020-15394Crítica (9.8)7.9%—25 sept 2020
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
CVE-2020-14008Alta (7.2)40%—4 sept 2020
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
CVE-2019-19799Media (5.3)6.4%—13 mar 2020
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
CVE-2014-7863Alta (7.5)83%—8 feb 2020
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access,…
CVE-2019-19800Media (5.3)3.9%—6 feb 2020
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1078.002 Domain Accounts2
  3. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Zohocorp