20 results (0.006 seconds)

CVSS: 9.0EPSS: 1%CPEs: 2EXPL: 1

25 Feb 2023 — Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.) • https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 10.0EPSS: 94%CPEs: 158EXPL: 14

18 Jan 2023 — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus befor... • https://packetstorm.news/files/id/170925 • CWE-20: Improper Input Validation •

CVSS: 5.3EPSS: 71%CPEs: 1EXPL: 2

02 Mar 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.8, expone el nombre del servidor instalado a cualquiera. El nombre de host interno puede ser detectado al leer las respuestas de redireccionamiento HTTP • https://github.com/fbusr/CVE-2022-23779 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.5EPSS: 3%CPEs: 1EXPL: 0

28 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.10, permite a un usuario autenticado cambiar la contraseña de acceso de cualquier usuario • https://www.manageengine.com/products/desktop-central/privilege-escalation-vulnerability.html •

CVSS: 9.1EPSS: 38%CPEs: 2EXPL: 0

18 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.9 y Desktop Central MSP versiones anteriores a 10.1.2137.9, permiten a atacantes omitir la autenticación y leer información confidencial o cargar un archivo ZIP arbitrario en el servidor • https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022 •

CVSS: 8.8EPSS: 3%CPEs: 1EXPL: 0

09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, permite una ejecución de código remota por parte de un usuario autenticado que tenga acceso completo al módulo de Informes • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, durante el inicio, lanza un archivo ejecutable desde los archivos por lotes, pero la ruta de este archivo podría no estar correctamente definida • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, permite a usuarios autenticados conseguir información confidencial de la base de datos al visitar la página de Informes • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 94%CPEs: 4EXPL: 1

12 Dec 2021 — Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. • https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 0

10 Sep 2021 — Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. Zoho ManageEngine DesktopCentral antes de la versión 10.0.709 permite a cualquiera obtener la APIKEY de un usuario válido sin necesidad de autenticación • https://www.manageengine.com/products/desktop-central/help/introduction/release_notes.html • CWE-287: Improper Authentication •