Записи ManageEngine
46 опубликованных записей вендора manageengine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 6 · 13 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 2,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-287 Improper Authentication2
- CWE-310 Cryptographic Issues1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
46 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2015-8249Готовый эксплойт | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary filmanageengine · desktop central · CWE-434 | Критическая9,8 | — | 73,6 % | 27 сент. 2017 г. |
59В плане | CVE-2014-5301Готовый эксплойт | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to manageengine · servicedesk plus · CWE-22 | Высокая8,8 | — | 78,4 % | 28 авг. 2017 г. |
54В плане | CVE-2017-11512Proof of concept | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nammanageengine · servicedesk · CWE-22 | Высокая7,5 | — | 79,6 % | 8 нояб. 2017 г. |
42В плане | CVE-2014-3996Готовый эксплойт | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Promanageengine · it360 · CWE-89 | Высокая7,5 | — | 38,4 % | 5 дек. 2014 г. |
42В плане | CVE-2007-2429Proof of concept | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command manageengine · passwordmanager pro | Критическая10,0 | — | 8,0 % | 1 мая 2007 г. |
42В плане | CVE-2014-9373Эксплойта нет | Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to executmanageengine · netflow analyzer · CWE-22 | Критическая10,0 | — | 6,3 % | 16 дек. 2014 г. |
40В плане | CVE-2016-9488Proof of concept | ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilitiesmanageengine · applications manager · CWE-89 | Критическая9,8 | — | 4,7 % | 5 июн. 2018 г. |
40В плане | CVE-2021-28960Эксплойта нет | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input commanmanageengine · desktop central · CWE-77 | Критическая9,8 | — | 2,0 % | 21 сент. 2021 г. |
38Наблюдать | CVE-2014-5302Эксплойта нет | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9manageengine · servicedesk plus · CWE-22 | Высокая8,8 | — | 10,7 % | 28 авг. 2017 г. |
37Наблюдать | CVE-2014-5377Готовый эксплойт | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials viamanageengine · device expert · CWE-200 | Средняя5,0 | — | 57,5 % | 4 сент. 2014 г. |
37Наблюдать | CVE-2014-8499Готовый эксплойт | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) emanageengine · password manager pro · CWE-89 | Средняя6,5 | — | 36,4 % | 17 нояб. 2014 г. |
32Наблюдать | CVE-2011-2757Готовый эксплойт | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read manageengine · servicedesk plus · CWE-22 | Средняя5,0 | — | 39,4 % | 17 июл. 2011 г. |
32Наблюдать | CVE-2014-8678Эксплойта нет | The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,manageengine · oputils · CWE-200 | Высокая7,8 | — | 2,3 % | 25 нояб. 2014 г. |
31Наблюдать | CVE-2017-11511Эксплойта нет | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filmanageengine · servicedesk · CWE-22 | Высокая7,5 | — | 3,6 % | 8 нояб. 2017 г. |
31Наблюдать | CVE-2010-4840Эксплойта нет | Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Symanageengine · eventlog analyzer · CWE-119 | Высокая7,5 | — | 2,2 % | 27 сент. 2011 г. |
30Наблюдать | CVE-2012-1063Эксплойта нет | Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commanageengine · applications manager · CWE-89 | Высокая7,5 | — | 1,3 % | 13 февр. 2012 г. |
30Наблюдать | CVE-2010-1044Proof of concept | SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpmanageengine · oputils · CWE-89 | Высокая7,5 | — | 1,0 % | 22 мар. 2010 г. |
29Наблюдать | CVE-2011-2755Proof of concept | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to readmanageengine · servicedesk plus · CWE-22 | Средняя5,0 | — | 30,9 % | 17 июл. 2011 г. |
26Наблюдать | CVE-2014-9372Эксплойта нет | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remotmanageengine · password manager pro · CWE-22 | Средняя6,4 | — | 2,4 % | 16 дек. 2014 г. |
25Наблюдать | CVE-2018-15608Proof of concept | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.manageengine · admanager plus · CWE-79 | Средняя6,1 | — | 2,5 % | 28 авг. 2018 г. |
25Наблюдать | CVE-2016-9490Эксплойта нет | ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerabilitymanageengine · applications manager · CWE-79 | Средняя6,1 | — | 1,7 % | 5 июн. 2018 г. |
25Наблюдать | CVE-2008-0476Эксплойта нет | ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows manageengine · applications manager · CWE-287 | Средняя6,4 | — | 1,2 % | 29 янв. 2008 г. |
24Наблюдать | CVE-2008-1299Эксплойта нет | Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote atmanageengine · servicedesk plus · CWE-79 | Средняя6,1 | — | 0,8 % | 12 мар. 2008 г. |
24Наблюдать | CVE-2020-19554Эксплойта нет | Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.manageengine · opmanager · CWE-79 | Средняя6,1 | — | 0,6 % | 21 сент. 2021 г. |
21Наблюдать | CVE-2011-2756Эксплойта нет | FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to remanageengine · servicedesk plus · CWE-287 | Средняя5,0 | — | 2,0 % | 17 июл. 2011 г. |
- CVE-2015-824961На этой неделе
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil
КритическаяCVSS 9,8Готовый эксплойтEPSS 74 %manageengine · desktop central27 сент. 2017 г.
- CVE-2014-530159В плане
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to
ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %manageengine · servicedesk plus28 авг. 2017 г.
- CVE-2017-1151254В плане
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam
ВысокаяCVSS 7,5Proof of conceptEPSS 80 %manageengine · servicedesk8 нояб. 2017 г.
- CVE-2014-399642В плане
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro
ВысокаяCVSS 7,5Готовый эксплойтEPSS 38 %manageengine · it3605 дек. 2014 г.
- CVE-2007-242942В плане
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command
КритическаяCVSS 10,0Proof of conceptEPSS 8 %manageengine · passwordmanager pro1 мая 2007 г.
- CVE-2014-937342В плане
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %manageengine · netflow analyzer16 дек. 2014 г.
- CVE-2016-948840В плане
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
КритическаяCVSS 9,8Proof of conceptEPSS 5 %manageengine · applications manager5 июн. 2018 г.
- CVE-2021-2896040В плане
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %manageengine · desktop central21 сент. 2021 г.
- CVE-2014-530238Наблюдать
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9
ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %manageengine · servicedesk plus28 авг. 2017 г.
- CVE-2014-537737Наблюдать
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via
СредняяCVSS 5,0Готовый эксплойтEPSS 57 %manageengine · device expert4 сент. 2014 г.
- CVE-2014-849937Наблюдать
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e
СредняяCVSS 6,5Готовый эксплойтEPSS 36 %manageengine · password manager pro17 нояб. 2014 г.
- CVE-2011-275732Наблюдать
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read
СредняяCVSS 5,0Готовый эксплойтEPSS 39 %manageengine · servicedesk plus17 июл. 2011 г.
- CVE-2014-867832Наблюдать
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %manageengine · oputils25 нояб. 2014 г.
- CVE-2017-1151131Наблюдать
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %manageengine · servicedesk8 нояб. 2017 г.
- CVE-2010-484031Наблюдать
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %manageengine · eventlog analyzer27 сент. 2011 г.
- CVE-2012-106330Наблюдать
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %manageengine · applications manager13 февр. 2012 г.
- CVE-2010-104430Наблюдать
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %manageengine · oputils22 мар. 2010 г.
- CVE-2011-275529Наблюдать
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read
СредняяCVSS 5,0Proof of conceptEPSS 31 %manageengine · servicedesk plus17 июл. 2011 г.
- CVE-2014-937226Наблюдать
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot
СредняяCVSS 6,4Эксплойта нетEPSS 2 %manageengine · password manager pro16 дек. 2014 г.
- CVE-2018-1560825Наблюдать
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
СредняяCVSS 6,1Proof of conceptEPSS 2 %manageengine · admanager plus28 авг. 2018 г.
- CVE-2016-949025Наблюдать
ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 2 %manageengine · applications manager5 июн. 2018 г.
- CVE-2008-047625Наблюдать
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows
СредняяCVSS 6,4Эксплойта нетEPSS 1 %manageengine · applications manager29 янв. 2008 г.
- CVE-2008-129924Наблюдать
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at
СредняяCVSS 6,1Эксплойта нетEPSS 1 %manageengine · servicedesk plus12 мар. 2008 г.
- CVE-2020-1955424Наблюдать
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %manageengine · opmanager21 сент. 2021 г.
- CVE-2011-275621Наблюдать
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re
СредняяCVSS 5,0Эксплойта нетEPSS 2 %manageengine · servicedesk plus17 июл. 2011 г.