QID 372459
QID 372459: Zoho ManageEngine AssetExplorer Remote code execution vulnerability
Zoho ManageEngine AssetExplorer is an application performance monitoring solution that monitors business applications.
Affected Versions:
Zoho ManageEngine AssetExplorer 6.5
QID Detection Logic:(authenticated)
This QID sends request to the windows registry, and checks release version of buildinfo.xml of AssetExplorer in windows.
Successful exploitation of the vulnerability will lead to Remote Code Execution.
Solution
Vendor has released to fix this vulnerability.
Vendor References
- CVE-2020-8838 -
www.manageengine.com/products/asset-explorer/sp-readme.html
CVEs related to QID 372459
Software Advisories
| Advisory ID | Software | Component | Link |
|---|