O365 Manager Plus
by Manageengine
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42099 | Cri | 0.64 | 9.8 | 0.07 | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. | ||
| CVE-2026-11374 | Cri | 0.59 | 9.0 | 0.03 | Jun 23, 2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | ||
| CVE-2021-44652 | Hig | 0.51 | 7.8 | 0.03 | Jan 12, 2022 | Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component. | ||
| CVE-2021-44650 | Hig | 0.47 | 7.2 | 0.05 | Jan 12, 2022 | Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components. | ||
| CVE-2022-24447 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2022 | An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export. | ||
| CVE-2021-28382 | Med | 0.35 | 5.4 | 0.01 | Jun 7, 2021 | Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. | ||
| CVE-2022-24446 | Med | 0.28 | 4.3 | 0.01 | Mar 1, 2022 | An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator. |
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
- risk 0.59cvss 9.0epss 0.03
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
- risk 0.51cvss 7.8epss 0.03
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
- risk 0.47cvss 7.2epss 0.05
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
- risk 0.35cvss 5.4epss 0.01
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.