Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. ManageEngine/
  3. ManageEngine ADManager Plus

ManageEngine ADManager Plus

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 100 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Unified AD and Microsoft 365 mgmt, reporting, and automation platform

by ManageEngine · manageengine.com · source ↗

Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2017-16847 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.

  • CVE-2017-16846 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

  • CVE-2017-11512 ↗HIGH 7.52017

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticate…

  • CVE-2017-11511 ↗HIGH 7.52017

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticate…

  • CVE-2017-16543 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

  • CVE-2017-16542 ↗HIGH 8.82017

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2015-8249 ↗CRITICAL 9.82017

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2017-14123 ↗HIGH 8.82017

    Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the serve…

  • CVE-2015-9107 ↗CRITICAL 9.82017

    Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or…

  • CVE-2017-11687 ↗MEDIUM 6.12017

    Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitra…

  • CVE-2017-11686 ↗MEDIUM 6.12017

    Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the pa…

  • CVE-2017-11685 ↗MEDIUM 6.12017

    Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web …

  • CVE-2017-11346 ↗CRITICAL 9.82017

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2015-7781 ↗HIGH 7.52017

    ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.

  • CVE-2015-7780 ↗MEDIUM 6.52017

    Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

  • CVE-2017-7213 ↗CRITICAL 10.02017

    Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

  • CVE-2016-1161 ↗HIGH 8.02017

    Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

  • CVE-2016-4890 ↗MEDIUM 5.32017

    ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a coo…

  • CVE-2016-4889 ↗HIGH 8.82017

    ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

  • CVE-2016-4888 ↗MEDIUM 5.42017

    Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • …and 80 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes