48 results (0.003 seconds)

CVSS: 9.0EPSS: 1%CPEs: 1EXPL: 0

03 Nov 2023 — A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests. Se ha encontrado una vulnerabilidad SSRF en ManageEngine Desktop Central que afecta a la versión 9.1.0, específicamente al componente /smtpConfig.do. Esta vulnerabilidad podría permitir que un atacante aut... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 6.4EPSS: 9%CPEs: 1EXPL: 0

03 Nov 2023 — A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. Se ha encontrado una vulnerabilidad de inyección CRLF en ManageEngine Desktop Central que afecta a la versión 9.1.0. Esta vulnerabilidad podría permitir a un atacante remoto inyectar encabezados HTTP arbitrario... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') •

CVSS: 6.4EPSS: 9%CPEs: 1EXPL: 0

03 Nov 2023 — A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. Se ha encontrado una vulnerabilidad de inyección CRLF en ManageEngine Desktop Central que afecta a la versión 9.1.0. Esta vulnerabilidad podría permitir a un atacante remoto inyectar encabezados HTTP arbitrario... • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-manageengine-desktop-central • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') •

CVSS: 9.0EPSS: 1%CPEs: 2EXPL: 1

25 Feb 2023 — Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.) • https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 10.0EPSS: 94%CPEs: 158EXPL: 14

18 Jan 2023 — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus befor... • https://packetstorm.news/files/id/170925 • CWE-20: Improper Input Validation •

CVSS: 5.3EPSS: 71%CPEs: 1EXPL: 2

02 Mar 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.8, expone el nombre del servidor instalado a cualquiera. El nombre de host interno puede ser detectado al leer las respuestas de redireccionamiento HTTP • https://github.com/fbusr/CVE-2022-23779 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.5EPSS: 3%CPEs: 1EXPL: 0

28 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.10, permite a un usuario autenticado cambiar la contraseña de acceso de cualquier usuario • https://www.manageengine.com/products/desktop-central/privilege-escalation-vulnerability.html •

CVSS: 9.1EPSS: 38%CPEs: 2EXPL: 0

18 Jan 2022 — Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. Zoho ManageEngine Desktop Central versiones anteriores a 10.1.2137.9 y Desktop Central MSP versiones anteriores a 10.1.2137.9, permiten a atacantes omitir la autenticación y leer información confidencial o cargar un archivo ZIP arbitrario en el servidor • https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022 •

CVSS: 8.8EPSS: 3%CPEs: 1EXPL: 0

09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, permite una ejecución de código remota por parte de un usuario autenticado que tenga acceso completo al módulo de Informes • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Jan 2022 — Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. Zoho ManageEngine Desktop Central versiones anteriores a 10.0.662, durante el inicio, lanza un archivo ejecutable desde los archivos por lotes, pero la ruta de este archivo podría no estar correctamente definida • https://www.manageengine.com/products/desktop-central/vulnerabilities-in-reports-module.html •