Zoho Vulnerabilities and Affected Products
Vulnerabilities associated with ManageEngine.
Products
Clear product- ManageEngine6 vulnerabilities
- manageengine_opmanager3 vulnerabilities
- ManageEngine ServiceDesk2 vulnerabilities
- campaigns1 vulnerability
- Desktop Central1 vulnerability
- firewall_analyzer1 vulnerability
- ManageEngine ServiceDesk Plus (SDP)1 vulnerability
- ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus1 vulnerability
- manageengine_access_manager_plus1 vulnerability
- manageengine_adaudit_plus1 vulnerability
- manageengine_admanager_plus1 vulnerability
- manageengine_adselfservice_plus1 vulnerability
- manageengine_firewall_analyzer1 vulnerability
- Password Manager Pro (PMP)1 vulnerability
- Zoho CRM Lead Magnet1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-47966CRITICAL | Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManage… | CVSS9.8v3.1 | EPSS99.8% | PoCs8 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-35405CRITICAL | Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityZoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) | CVSS9.8v3.1 | EPSS>99.9% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-28810MEDIUM | Zoho ManageEngine ADSelfService Plus Remote Code Execution VulnerabilityZoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field. | CVSS6.8v3.1 | EPSS71% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40539CRITICAL | Zoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilityZoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | CVSS9.8v3.1 | EPSS99% | PoCs6 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2020-10189CRITICAL | Zoho ManageEngine Desktop Central File Upload VulnerabilityZoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets. | CVSS9.8v3.1 | EPSS>99.9% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-8394HIGH | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload VulnerabilityZoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. CWE-434Feb 17, 2019 | CVSS7.5v3.1 | EPSS63.3% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |