VYPR

Manageengine Applications Manager

by Zohocorp

CVEs (30)

  • CVE-2017-16543CriNov 5, 2017
    risk 0.67cvss 9.8epss 0.06

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

  • CVE-2017-16851CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.

  • CVE-2017-16850CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.

  • CVE-2017-16849CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.

  • CVE-2017-16848CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.15

    Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

  • CVE-2017-16847CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.

  • CVE-2017-16846CriNov 16, 2017
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

  • CVE-2017-16542HigNov 5, 2017
    risk 0.61cvss 8.8epss 0.05

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2018-11808CriJun 6, 2018
    risk 0.60cvss 9.1epss 0.06

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by…

  • CVE-2025-9223HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.04

    Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

  • CVE-2018-12996MedJun 29, 2018
    risk 0.40cvss 6.1epss 0.03

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.

  • CVE-2014-7863Feb 8, 2020
    risk 0.10cvss epss 0.83

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users…

  • CVE-2018-7890CriMar 8, 2018
    risk 0.09cvss 9.8epss 0.79

    A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls…

  • CVE-2023-28341Apr 11, 2023
    risk 0.05cvss epss 0.99

    Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

  • CVE-2019-19649Dec 11, 2019
    risk 0.04cvss epss 0.10

    Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

  • CVE-2019-11469Apr 23, 2019
    risk 0.04cvss epss 0.18

    Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

  • CVE-2019-11448Apr 22, 2019
    risk 0.04cvss epss 0.12

    An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to…

  • CVE-2019-15105Aug 16, 2019
    risk 0.03cvss epss 0.08

    An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can…

  • CVE-2023-28340Apr 11, 2023
    risk 0.01cvss epss 0.03

    Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

  • CVE-2019-19799Mar 13, 2020
    risk 0.01cvss epss 0.06

    Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

Page 1 of 2