Page 11 of 488 results (0.006 seconds)

CVSS: 9.4EPSS: 1%CPEs: 108EXPL: 0

10 Aug 2022 — Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs. Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer y OpUtils versiones anteriores a 27-07-2022 hasta 28-07-2022 (125657, 126002, 12... • https://www.manageengine.com/itom/advisory/cve-2022-36923.html • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 9.0EPSS: 58%CPEs: 108EXPL: 0

09 Aug 2022 — Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution. Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer y OpUtils versiones anteriores a 29-07-2022 hasta 30-07-2022 ( 125658, 126003, 126105 y 126120) permiten a usuarios auten... • https://www.manageengine.com/itom/advisory/cve-2022-37024.html •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

26 Jul 2022 — In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) En Zoho ManageEngine SupportCenter Plus versiones anteriores a 11023, las peticiones de la API versión V3 son vulnerables a una omisión de la autenticación. (Una petición API puede, en efecto, ser ejecutada con las credenciales de un usuario que fue autenticado en el pasado). • https://www.manageengine.com/products/support-center/cve-2022-36412.html • CWE-287: Improper Authentication •

CVSS: 10.0EPSS: 94%CPEs: 8EXPL: 3

19 Jul 2022 — Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) Zoho ManageEngine Password Manager Pro versiones anteriores a 12101 y PAM360 versiones anteriores a 5510, son vulnerables a una ejecución de código remota sin autenticación. (Esto también afecta a ManageEngine Access Manager Plus versiones anteriores a 4303 con autenticación). Zoho ManageEngin... • https://packetstorm.news/files/id/167918 • CWE-502: Deserialization of Untrusted Data •

CVSS: 8.5EPSS: 0%CPEs: 336EXPL: 0

18 Jul 2022 — ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine. ManageEngine Password Manager Pro versiones 12100 y anteriores y OPManager versiones 126100 y anteriores son vulnerables a una creación no autorizada de archivos y directorios en un equipo servidor • https://manageengine.com • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 1%CPEs: 65EXPL: 0

12 Jul 2022 — Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.) Zoho ManageEngine ServiceDesk Plus versiones anteriores a 13008, ServiceDesk Plus MSP versiones anteriores a 10606 y SupportCenter Plus versiones anteriores a 11022 están afectados por una vulnerabilidad de divulgación de arch... • https://www.manageengine.com/products/service-desk/cve-2022-35403.html •

CVSS: 7.5EPSS: 1%CPEs: 4EXPL: 0

04 Jul 2022 — Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API. Zoho ManageEngine ADSelfService Plus versiones anteriores a 6203, permite una denegación de servicio (reinicio de la aplicación) por medio de una carga útil diseñada para la API de despliegue de aplicaciones móviles • https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-34829.html •

CVSS: 7.5EPSS: 2%CPEs: 6EXPL: 0

01 Jul 2022 — Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). Zoho ManageEngine ServiceDesk Plus MSP versiones anteriores a 10604 permite un salto de ruta (a WEBINF/web.xml desde sample/WEB-INF/web.xml o sample/META-INF/web.xml) • https://www.manageengine.com/products/service-desk-msp/CVE-2022-32551.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.2EPSS: 27%CPEs: 4EXPL: 1

24 May 2022 — ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. ManageEngine AppManager15 (Build No:15510) permite a un usuario administrador autenticado subir un archivo DLL para llevar a cabo un ataque de secuestro de DLL dentro de la carpeta "working" mediante la funcionalidad "Upload Files / Binaries" • https://fluidattacks.com/advisories/cerati • CWE-427: Uncontrolled Search Path Element •

CVSS: 5.3EPSS: 1%CPEs: 1EXPL: 2

20 May 2022 — Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login. Zoho ManageEngine ADSelfService Plus antes de la versión 6202 permite a los atacantes realizar una enumeración de nombres de usuario a través de una solicitud POST elaborada a /ServletAPI/accounts/login • https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/adselfservice-userenum.md •