High severity8.8NVD Advisory· Published Feb 5, 2021· Updated Jun 17, 2026
CVE-2020-35765
CVE-2020-35765
Description
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*range: <14.9
- cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:-:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14900:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14910:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14911:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14930:*:*:*:*:*:*
- Zoho/ManageEngine Applications Managerdescription
- Range: <=14930
Patches
Vulnerability mechanics
References
4- www.tenable.com/security/research/tra-2021-02nvdExploitThird Party Advisory
- www.manageengine.comnvdVendor Advisory
- www.manageengine.com/products/applications_manager/issues.htmlnvdRelease NotesVendor Advisory
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-35765.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.