CVE-2020-24786
Summary
| CVE | CVE-2020-24786 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-31 15:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ManageEngine Log360 - Security advisory regarding unauthenticated product integration vulnerability. | MISC | pitstop.manageengine.com | Vendor Advisory |
| How to fix the unauthenticated product integration vulnerability | MISC | pitstop.manageengine.com | Vendor Advisory |
| How to identify and mitigate the unauthenticated product integration vulnerability. | MISC | pitstop.manageengine.com | Vendor Advisory |
| ADManager Plus Fixes and Enhancements | MISC | pitstop.manageengine.com | Vendor Advisory |
| How to fix the unauthenticated product integration vulnerability | MISC | pitstop.manageengine.com | Vendor Advisory |
| How to fix the unauthenticated product integration vulnerability | MISC | pitstop.manageengine.com | Vendor Advisory |
| Release notes | ManageEngine DataSecurity Plus | MISC | www.manageengine.com | Vendor Advisory |
| How to identify and mitigate the unauthenticated product integration vulnerability? | MISC | pitstop.manageengine.com | Vendor Advisory |
| Eventlog Analyzer Latest Features | MISC | www.manageengine.com | Vendor Advisory |
| How to identify and mitigate the unauthenticated product integration vulnerability? | MISC | pitstop.manageengine.com | Vendor Advisory |
| ManageEngine Cloud Security Plus - Security advisory regarding unauthenticated product integration vulnerability. | MISC | pitstop.manageengine.com | Vendor Advisory |
| Another Zoho ManageEngine Story - frycos - Medium | MISC | medium.com | Third Party Advisory |
| Another Zoho ManageEngine Story. This is another white-box analysis… | by frycos | Medium | medium.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375802 Zoho ManageEngine ADManager Plus Unauthenticated Product Integration Vulnerability