VYPR

Manageengine Applications Manager

by Zohocorp

CVEs (57)

  • CVE-2017-16542HigNov 5, 2017
    risk 0.61cvss 8.8epss 0.05

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2020-15927HigOct 6, 2020
    risk 0.60cvss 8.8epss 0.43

    Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

  • CVE-2018-11808CriJun 6, 2018
    risk 0.60cvss 9.1epss 0.06

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by…

  • CVE-2020-35765HigFeb 5, 2021
    risk 0.59cvss 8.8epss 0.27

    doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

  • CVE-2025-9223HigNov 11, 2025
    risk 0.58cvss 8.8epss 0.04

    Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

  • CVE-2020-27733HigJan 19, 2021
    risk 0.58cvss 8.8epss 0.09

    Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

  • CVE-2014-7863HigFeb 8, 2020
    risk 0.58cvss 7.5epss 0.83

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users…

  • CVE-2019-19650HigDec 11, 2019
    risk 0.58cvss 8.8epss 0.06

    Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.

  • CVE-2020-28679HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

  • CVE-2019-19475HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can…

  • CVE-2017-11740HigMay 23, 2019
    risk 0.57cvss 8.8epss 0.03

    In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the…

  • CVE-2016-9489HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another…

  • CVE-2018-16364HigSep 26, 2018
    risk 0.54cvss 8.1epss 0.18

    A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

  • CVE-2024-41140HigJan 29, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

  • CVE-2020-14008HigSep 4, 2020
    risk 0.53cvss 7.2epss 0.40

    Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

  • CVE-2017-11738HigMay 23, 2019
    risk 0.53cvss 8.1epss 0.04

    In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.

  • CVE-2020-10816HigOct 8, 2020
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.

  • CVE-2023-28341MedApr 11, 2023
    risk 0.48cvss 6.1epss 0.99

    Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

  • CVE-2022-23050HigMay 24, 2022
    risk 0.47cvss 7.2epss 0.05

    ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.

  • CVE-2023-28340MedApr 11, 2023
    risk 0.43cvss 6.5epss 0.03

    Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.