ManageEngine Vulnerabilities and Affected Products
Vulnerabilities associated with adaudit_plus.
Products
Clear product- ADAudit Plus35 vulnerabilities
- adaudit_plus25 vulnerabilities
- Applications Manager8 vulnerabilities
- Exchange Reporter Plus8 vulnerabilities
- ADSelfService Plus5 vulnerabilities
- OpManager5 vulnerabilities
- Endpoint Central4 vulnerabilities
- ServiceDesk Plus MSP4 vulnerabilities
- Desktop Central3 vulnerabilities
- exchange_reporter_plus3 vulnerabilities
- PAM3603 vulnerabilities
- ServiceDesk Plus3 vulnerabilities
- SupportCenter Plus3 vulnerabilities
- ADManager Plus2 vulnerabilities
- Analytics Plus2 vulnerabilities
- Asset Explorer2 vulnerabilities
- DDI Central2 vulnerabilities
- servicedesk2 vulnerabilities
- Access Manager Plus1 vulnerability
- desktop_central1 vulnerability
- OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition1 vulnerability
- OpManager, Remote Monitoring and Management1 vulnerability
- Password Manager Pro1 vulnerability
- password_manager_pro1 vulnerability
- Service Desk Plus1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-5608HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature. CWE-89Oct 24, 2024 | CVSS8.3v3.1 | EPSS2.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5586HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS5.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5556HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5490HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36514HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36515HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36516HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36517HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS5.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5467HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report. CWE-89Aug 23, 2024 | CVSS8.3v3.1 | EPSS4.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36034HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. CWE-89Aug 12, 2024 | CVSS8.3v3.1 | EPSS7.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36035HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. CWE-89Aug 12, 2024 | CVSS8.3v3.1 | EPSS7.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36518HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard. CWE-89Aug 12, 2024 | CVSS8.3v3.1 | EPSS3.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5487HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. CWE-89Aug 12, 2024 | CVSS8.3v3.1 | EPSS4.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5527HIGH | SQL InjectionZohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration. CWE-89Aug 12, 2024 | CVSS8.3v3.1 | EPSS4.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36037MEDIUM | Insufficient Access Control VulnerabilityZoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings. CWE-863May 27, 2024 | CVSS5.5v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49335HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS3.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49334HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS3.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49333HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS3.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49332HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS3.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49331HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS3.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49330HIGH | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data. CWE-89May 20, 2024 | CVSS8.3v3.1 | EPSS2.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0269HIGH | SQL InjectionManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271. CWE-89Feb 2, 2024 | CVSS8.3v3.1 | EPSS5.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0253HIGH | SQL InjectionManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data. CWE-89Feb 2, 2024 | CVSS8.3v3.1 | EPSS5.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-48792CRITICAL | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. CWE-89Feb 2, 2024 | CVSS9.8v3.1 | EPSS6.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-48793CRITICAL | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. CWE-89Feb 2, 2024 | CVSS9.8v3.1 | EPSS6.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |