ManageEngine ITOM
by Zoho
CVEs (35)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-8929 | Med | 0.44 | 6.1 | 0.11 | May 17, 2019 | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype. | ||
| CVE-2019-15083 | Med | 0.43 | 6.1 | 0.06 | May 14, 2020 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine… | ||
| CVE-2019-12189 | Med | 0.43 | 6.1 | 0.06 | May 21, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. | ||
| CVE-2024-36038 | Med | 0.41 | 6.3 | 0.01 | Jun 24, 2024 | Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option. | ||
| CVE-2020-27449 | Med | 0.40 | 6.1 | 0.03 | Aug 11, 2023 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload. | ||
| CVE-2021-27956 | Med | 0.40 | 6.1 | 0.02 | May 20, 2021 | Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. | ||
| CVE-2019-12596 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | ||
| CVE-2019-12595 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | ||
| CVE-2019-12540 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. | ||
| CVE-2022-26653 | Med | 0.35 | 5.3 | 0.02 | Apr 16, 2022 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). | ||
| CVE-2021-33617 | Med | 0.35 | 5.3 | 0.02 | Jul 31, 2021 | Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid. | ||
| CVE-2019-19799 | Med | 0.35 | 5.3 | 0.06 | Mar 13, 2020 | Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. | ||
| CVE-2019-15045 | Med | 0.35 | 5.3 | 0.05 | Aug 21, 2019 | AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality | ||
| CVE-2014-6036 | 0.06 | — | 0.36 | Dec 4, 2014 | Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the… | |||
| CVE-2014-7864 | 0.05 | — | 0.23 | Feb 4, 2015 | Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1)… |
- risk 0.44cvss 6.1epss 0.11
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
- risk 0.43cvss 6.1epss 0.06
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine…
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
- risk 0.41cvss 6.3epss 0.01
Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.
- risk 0.40cvss 6.1epss 0.03
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
- risk 0.35cvss 5.3epss 0.02
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
- risk 0.35cvss 5.3epss 0.02
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
- risk 0.35cvss 5.3epss 0.06
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
- risk 0.35cvss 5.3epss 0.05
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
- CVE-2014-6036Dec 4, 2014risk 0.06cvss —epss 0.36
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the…
- CVE-2014-7864Feb 4, 2015risk 0.05cvss —epss 0.23
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1)…
Page 2 of 2