Known Vulnerabilities for Manageengine Applications Manager by Zohocorp

Listed below are 10 of the newest known vulnerabilities associated with "Manageengine Applications Manager" by "Zohocorp".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-23050 ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack at... 7.2 - HIGH 2022-05-24 2023-08-08
CVE-2021-35512 An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. 6.5 - MEDIUM 2021-10-21 2021-10-28
CVE-2021-31813 Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g.,... 5.4 - MEDIUM 2021-07-01 2021-09-21
CVE-2020-16267 Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp reques... 8.8 - HIGH 2020-10-06 2020-10-14
CVE-2020-15927 Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp reques... 8.8 - HIGH 2020-10-06 2020-10-14
CVE-2020-15533 In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation mo... 9.8 - CRITICAL 2020-10-01 2020-10-13
CVE-2020-15521 Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (X... 6.1 - MEDIUM 2020-09-25 2020-09-30
CVE-2020-15394 The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a craft... 9.8 - CRITICAL 2020-09-25 2020-09-30
CVE-2020-14008 Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a sp... 7.2 - HIGH 2020-09-04 2020-09-16
CVE-2020-10816 Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers ... 7.5 - HIGH 2020-10-08 2020-10-15

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationZohocorpManageengine Applications Manager15.0-AllAll
ApplicationZohocorpManageengine Applications Manager15.0build15000AllAll
ApplicationZohocorpManageengine Applications Manager15.0build15010AllAll
ApplicationZohocorpManageengine Applications Manager15.0build15020AllAll
ApplicationZohocorpManageengine Applications Manager15.0build15030AllAll
ApplicationZohocorpManageengine Applications Manager15.0build15040AllAll
ApplicationZohocorpManageengine Applications Manager14.9-AllAll
ApplicationZohocorpManageengine Applications Manager14.9build14900AllAll
ApplicationZohocorpManageengine Applications Manager14.9build14910AllAll
ApplicationZohocorpManageengine Applications Manager14.9build14911AllAll
ApplicationZohocorpManageengine Applications Manager14.9build14930AllAll
ApplicationZohocorpManageengine Applications Manager14.8AllAllAll
ApplicationZohocorpManageengine Applications Manager14.7AllAllAll
ApplicationZohocorpManageengine Applications Manager14.7-AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14700AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14710AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14720AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14730AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14740AllAll
ApplicationZohocorpManageengine Applications Manager14.7build14750AllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report