Show filters
506 Total Results
Displaying 111-120 of 506
Sort by:
Attacker Value
Unknown
CVE-2023-22624
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
0
Attacker Value
Unknown
CVE-2022-47523
Disclosure Date: January 05, 2023 (last updated February 24, 2025)
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2022-47578
Disclosure Date: December 20, 2022 (last updated February 24, 2025)
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by booting into Safe Mode. This allows a file to be exchanged outside the laptop/system. Safe Mode can be launched by any user (even without admin rights). Data exfiltration can occur, and also malware might be introduced onto the system. NOTE: the vendor's position is "it's not a vulnerability in our product."
0
Attacker Value
Unknown
CVE-2022-47577
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by making use of a virtual machine (VM). This allows a file to be exchanged outside the laptop/system. VMs can be created by any user (even without admin rights). The data exfiltration can occur without any record in the audit trail of Windows events on the host machine. NOTE: the vendor's position is "it's not a vulnerability in our product."
0
Attacker Value
Unknown
CVE-2022-40772
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
0
Attacker Value
Unknown
CVE-2022-40771
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
0
Attacker Value
Unknown
CVE-2022-40770
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
0
Attacker Value
Unknown
CVE-2022-42904
Disclosure Date: November 18, 2022 (last updated December 22, 2024)
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
0
Attacker Value
Unknown
CVE-2022-42903
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
0
Attacker Value
Unknown
CVE-2022-43672
Disclosure Date: November 12, 2022 (last updated February 24, 2025)
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
0