Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown

CVE-2021-41075

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
Attacker Value
Unknown

CVE-2021-41288

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
Attacker Value
Unknown

CVE-2020-19554

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
Attacker Value
Unknown

CVE-2021-20078

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
Attacker Value
Unknown

CVE-2020-13818

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
Attacker Value
Unknown

CVE-2020-11946

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
Attacker Value
Unknown

CVE-2020-11527

Disclosure Date: April 04, 2020 (last updated November 27, 2024)
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
Attacker Value
Unknown

CVE-2020-10541

Disclosure Date: March 13, 2020 (last updated November 27, 2024)
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
Attacker Value
Unknown

CVE-2014-7863

Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
Attacker Value
Unknown

CVE-2019-17421

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.