
CVE-2022-47966 – Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-47966
18 Jan 2023 — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus befor... • https://packetstorm.news/files/id/170925 • CWE-20: Improper Input Validation •

CVE-2022-24447
https://notcve.org/view.php?id=CVE-2022-24447
02 Mar 2022 — An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export. Se ha detectado un problema en Zoho ManageEngine Key Manager Plus versiones anteriores a 6200. Un servicio expuesto por la aplicación permite a un usuario, con el nivel de Operador, acceder a certificados SSL almacenados y a los pares de claves asociados durante la exportación • https://excellium-services.com/cert-xlm-advisory/cve-2022-24447 •

CVE-2021-28382
https://notcve.org/view.php?id=CVE-2021-28382
07 Jun 2021 — Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. Zoho ManageEngine Key Manager Plus versiones anteriores a 6001, permite ataques de tipo XSS almacenado en la página user-management al importar detalles de usuarios maliciosos desde el AD • https://raxis.com/blog/cve-2021-28382 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •