
CVE-2019-11361
https://notcve.org/view.php?id=CVE-2019-11361
19 Mar 2020 — Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover. Zoho ManageEngine Remote Access Plus versión 10.0.258, no comprueba los permisos del usuario apropiadamente, lo que permite una escalada de privilegios y, eventualmente, una toma de control de la aplicación completa. • https://www.manageengine.com/remote-desktop-management/knowledge-base/elevation-of-privilege.html • CWE-863: Incorrect Authorization •

CVE-2020-8422
https://notcve.org/view.php?id=CVE-2020-8422
31 Jan 2020 — An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password). Se detectó un problema de autorización en la funcionalidad Credential Manager en Zoho ManageEngine Remote Access Plus versiones anteriores a 10.0.450. Un usuario con el r... • https://excellium-services.com/cert-xlm-advisory/CVE-2020-8422 •