
CVE-2023-4769 – Server-Side Request Forgery in ManageEngine Desktop Central
https://notcve.org/view.php?id=CVE-2023-4769
03 Nov 2023 — A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests. Se ha encontrado una vulnerabilidad SSRF en ManageEngine Desktop Central que afecta a la versión 9.1.0, específicamente al componente /smtpConfig.do. Esta vulnerabilidad podría permitir que un atacante aut... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2023-4768 – Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
https://notcve.org/view.php?id=CVE-2023-4768
03 Nov 2023 — A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. Se ha encontrado una vulnerabilidad de inyección CRLF en ManageEngine Desktop Central que afecta a la versión 9.1.0. Esta vulnerabilidad podría permitir a un atacante remoto inyectar encabezados HTTP arbitrario... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') •

CVE-2023-4767 – Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
https://notcve.org/view.php?id=CVE-2023-4767
03 Nov 2023 — A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. Se ha encontrado una vulnerabilidad de inyección CRLF en ManageEngine Desktop Central que afecta a la versión 9.1.0. Esta vulnerabilidad podría permitir a un atacante remoto inyectar encabezados HTTP arbitrario... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') •

CVE-2022-48362
https://notcve.org/view.php?id=CVE-2022-48362
25 Feb 2023 — Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.) • https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2022-47966 – Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-47966
18 Jan 2023 — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus befor... • https://packetstorm.news/files/id/170925 • CWE-20: Improper Input Validation •

CVE-2022-23779
https://notcve.org/view.php?id=CVE-2022-23779
02 Mar 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.8, expone el nombre del servidor instalado a cualquiera. El nombre de host interno puede ser detectado al leer las respuestas de redireccionamiento HTTP • https://github.com/fbusr/CVE-2022-23779 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-23863
https://notcve.org/view.php?id=CVE-2022-23863
28 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.10, permite a un usuario autenticado cambiar la contraseña de acceso de cualquier usuario • https://www.manageengine.com/products/desktop-central/privilege-escalation-vulnerability.html •

CVE-2021-44757
https://notcve.org/view.php?id=CVE-2021-44757
18 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.9 y Desktop Central MSP versiones anteriores a 10.1.2137.9, permiten a atacantes omitir la autenticación y leer información confidencial o cargar un archivo ZIP arbitrario en el servidor • https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022 •

CVE-2021-46164
https://notcve.org/view.php?id=CVE-2021-46164
09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, permite una ejecución de código remota por parte de un usuario autenticado que tenga acceso completo al módulo de Informes • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •

CVE-2021-46165
https://notcve.org/view.php?id=CVE-2021-46165
09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, durante el inicio, lanza un archivo ejecutable desde los archivos por lotes, pero la ruta de este archivo podría no estar correctamente definida • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •