Show filters
506 Total Results
Displaying 111-120 of 506
Sort by:
Attacker Value
Unknown

CVE-2023-22624

Disclosure Date: January 17, 2023 (last updated February 24, 2025)
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
Attacker Value
Unknown

CVE-2022-47523

Disclosure Date: January 05, 2023 (last updated February 24, 2025)
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2022-47578

Disclosure Date: December 20, 2022 (last updated February 24, 2025)
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by booting into Safe Mode. This allows a file to be exchanged outside the laptop/system. Safe Mode can be launched by any user (even without admin rights). Data exfiltration can occur, and also malware might be introduced onto the system. NOTE: the vendor's position is "it's not a vulnerability in our product."
Attacker Value
Unknown

CVE-2022-47577

Disclosure Date: December 20, 2022 (last updated November 08, 2023)
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by making use of a virtual machine (VM). This allows a file to be exchanged outside the laptop/system. VMs can be created by any user (even without admin rights). The data exfiltration can occur without any record in the audit trail of Windows events on the host machine. NOTE: the vendor's position is "it's not a vulnerability in our product."
Attacker Value
Unknown

CVE-2022-40772

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
Attacker Value
Unknown

CVE-2022-40771

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
Attacker Value
Unknown

CVE-2022-40770

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Attacker Value
Unknown

CVE-2022-42904

Disclosure Date: November 18, 2022 (last updated December 22, 2024)
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
Attacker Value
Unknown

CVE-2022-42903

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
Attacker Value
Unknown

CVE-2022-43672

Disclosure Date: November 12, 2022 (last updated February 24, 2025)
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.