National Vulnerability Database

National Vulnerability Database

National Vulnerability

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/a:zohocorp:manageengine_applications_manager:14.1
There are 2 matching records.
Vuln ID Summary CVSS Severity

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

Published: August 15, 2019; 11:15:11 PM -04:00
V3.0: 8.8 HIGH
    V2: 9.0 HIGH

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

Published: September 26, 2018; 05:29:01 PM -04:00
V3.0: 8.1 HIGH
    V2: 9.3 HIGH